← Vulnerability feed

Vulnerability record · CVE-2022-31805 · published 24 June 2022

CVE-2022-31805: Codesys development system vulnerability

Codesys · Development System

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

7.5 CVSS 3.1 High EPSS 1.0% · top 38.0% CWE-523 · CWE-523
7.5CVSS 3.1 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31805 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31802Codesys gateway vulnerabilityIn CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway p…EPSS 1.3%9.8CVE-2019-9010Codesys control for beaglebone sl vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All …EPSS 1.9%9.8CVE-2018-10612Codesys control for beaglebone sl improper access control vulnerabilityIn 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not…EPSS 1.3%8.8CVE-2022-4046Codesys control for beaglebone sl memory buffer overflow vulnerabilityIn CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user …EPSS 0.88%8.8CVE-2023-3663Codesys development system vulnerabilityIn CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker t…EPSS 1.0%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.5CVE-2026-44469Codesys development system incorrect default permissions vulnerabilityThe affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A lo…EPSS 0.12%

Source: NIST National Vulnerability Database (record CVE-2022-31805), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.