PT-2022-20944 · 3S Smart Software Solutions · Codesys Gateway Server V2
Published
2022-06-24
·
Updated
2022-07-01
·
CVE-2022-31804
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CODESYS Gateway Server V2
Description
The issue arises from the failure of the CODESYS Gateway Server V2 to verify that the size of a request is within expected limits. This allows an unauthenticated attacker to allocate an arbitrary amount of memory, potentially leading to a crash of the Gateway due to an out-of-memory condition.
Recommendations
For CODESYS Gateway Server V2, consider implementing size verification for incoming requests to prevent arbitrary memory allocation until a patch is available. As a temporary workaround, monitor system resources closely to detect and respond to potential out-of-memory conditions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codesys Gateway Server V2