CVE-2022-1794

MEDIUM

CODESYS OPC DA Server <V3.5.18.20 - Info Disclosure

Title source: llm
STIX 2.1

Description

The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-256 CWE-522
Status published
Products (1)
codesys/opc_da_server 3.0.0 - 3.5.18.20
Published Jul 11, 2022
Tracked Since Feb 18, 2026