CVE Published: 11/07/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: CERTVDE |
Vendor: CODESYS |
Product: CODESYS OPC DA Server Status : PUBLISHED
CVE-2022-1794 Description
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N