Record summary

CVE-2022-31802 has a selected CVSS score of 9.8 (critical).

Description

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListV2 to < V2.3.9.38affected

References

2