Vulnerability Description
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codesys | Gateway | >= 2.0, < 2.3.9.38 |
Related Weaknesses (CWE)
References
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17141&token=17867e35cVendor Advisory
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=17141&token=17867e35cVendor Advisory
FAQ
What is CVE-2022-31804?
CVE-2022-31804 is a vulnerability with a CVSS score of 7.5 (HIGH). The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash o...
How severe is CVE-2022-31804?
CVE-2022-31804 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31804?
Check the references section above for vendor advisories and patch information. Affected products include: Codesys Gateway.