CVE-2022-31805
Published Jun 24, 2022In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
2 CVEs tagged to codesys / sp_realtime_nt — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.