PT-2022-20944 · 3S Smart Software Solutions · Codesys Gateway Server V2

Published

2022-06-24

·

Updated

2022-07-01

·

CVE-2022-31804

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Gateway Server V2
Description The issue arises from the failure of the CODESYS Gateway Server V2 to verify that the size of a request is within expected limits. This allows an unauthenticated attacker to allocate an arbitrary amount of memory, potentially leading to a crash of the Gateway due to an out-of-memory condition.
Recommendations For CODESYS Gateway Server V2, consider implementing size verification for incoming requests to prevent arbitrary memory allocation until a patch is available. As a temporary workaround, monitor system resources closely to detect and respond to potential out-of-memory conditions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31804

Affected Products

Codesys Gateway Server V2