QID 591223

Date Published: 2022-12-12

QID 591223: 3S-Smart CODESYS GmbH Visualization Observable Response Discrepancy Vulnerability (Advisory 2022-14)

AFFECTED PRODUCTS
All CODESYS Visualization versions prior to V4.2.0.0 provide a weak login dialog and inject it into the generated code, which is downloaded to and executed by the HMI or PLC.
CODESYS Visualization versions prior to V3.5.17.0 were provided as integrated plugins of the CODESYS Development System. This means that all CODESYS Development System versions before V3.5.17.0 generate a vulnerable login-dialog.
As of CODESYS Development System V3.5.17.0, CODESYS Visualization is provided as an optional Add-on and can be updated separately. CODESYS Visualization V4.0.0.0 was the first version to be made available as an optional Add-on and delivered together with CODESYS Development System V3.5.17.0. Thus, the Visualization Add-on versions from V4.0.0.0 and before V4.2.0.0 generate a vulnerable login-dialog.

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Login-dialog of the CODESYS Visualization discloses the information whether a user is existing or not.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    The vendor has released a patch version , for more information kindly visit Advisory 2022-14

    CVEs related to QID 591223

    Software Advisories
    Advisory ID Software Component Link
    Advisory 2022-14 URL Logo customers.codesys.com/index.php?eID=dumpFile&t=f&f=17142&token=a3696ab41fef800d2eaee8043d4 0d5fbe94277fd&download=

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report