CVE-2022-31806
Summary
| CVE | CVE-2022-31806 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-24 08:15:00 UTC |
| Updated | 2022-07-07 13:41:00 UTC |
| Description | In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller. |
Risk And Classification
Problem Types: CWE-1188
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Codesys | Plcwinnt | All | All | All | All |
| Application | Codesys | Runtime Toolkit | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| customers.codesys.com/index.php | CONFIRM | customers.codesys.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.