Medium severity5.5NVD Advisory· Published Jul 11, 2022· Updated Jun 17, 2026
CVE-2022-1794
CVE-2022-1794
Description
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
Affected products
3cpe:2.3:a:codesys:opc_da_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:codesys:opc_da_server:*:*:*:*:*:*:*:*range: >=3.0.0,<3.5.18.20
- (no CPE)range: <3.5.18.20
- (no CPE)range: V3
Patches
Vulnerability mechanics
References
1- customers.codesys.com/index.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.