VYPR
Medium severity5.5NVD Advisory· Published Jul 11, 2022· Updated Jun 17, 2026

CVE-2022-1794

CVE-2022-1794

Description

The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.

Affected products

3
  • cpe:2.3:a:codesys:opc_da_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:codesys:opc_da_server:*:*:*:*:*:*:*:*range: >=3.0.0,<3.5.18.20
    • (no CPE)range: <3.5.18.20
    • (no CPE)range: V3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.