QID 591223
Date Published: 2022-12-12
QID 591223: 3S-Smart CODESYS GmbH Visualization Observable Response Discrepancy Vulnerability (Advisory 2022-14)
AFFECTED PRODUCTS
All CODESYS Visualization versions prior to V4.2.0.0 provide a weak login dialog and inject it into the generated
code, which is downloaded to and executed by the HMI or PLC.
CODESYS Visualization versions prior to V3.5.17.0 were provided as integrated plugins of the CODESYS
Development System. This means that all CODESYS Development System versions before V3.5.17.0 generate
a vulnerable login-dialog.
As of CODESYS Development System V3.5.17.0, CODESYS Visualization is provided as an optional Add-on
and can be updated separately. CODESYS Visualization V4.0.0.0 was the first version to be made available as
an optional Add-on and delivered together with CODESYS Development System V3.5.17.0. Thus, the
Visualization Add-on versions from V4.0.0.0 and before V4.2.0.0 generate a vulnerable login-dialog.
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Login-dialog of the CODESYS Visualization discloses the information whether a user is existing or not.
CVEs related to QID 591223
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Advisory 2022-14 |
|