Lucene search

K
cvelistCERTVDECVELIST:CVE-2022-31803
HistoryJun 09, 2022 - 12:00 a.m.

CVE-2022-31803 CODESYS Gateway Server V2 prone to Denial of Service Attack

2022-06-0900:00:00
CWE-400
CERTVDE
www.cve.org
1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.3%

In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all available TCP connections and prevent legitimate users or clients from establishing a new connection to the CODESYS Gateway Server V2. Existing connections are not affected and therefore remain intact.

CNA Affected

[
  {
    "product": "CODESYS Gateway Server V2",
    "vendor": "CODESYS",
    "versions": [
      {
        "lessThan": "V2.3.9.38",
        "status": "affected",
        "version": "V2",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.3%

Related for CVELIST:CVE-2022-31803