← back
CVE-2022-31804highCWE-789

CODESYS Gateway server prone to denial of service attack due to excessive memory allocation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H