#VU112094 Partial String Comparison in CODESYS Gateway Server V2 - CVE-2022-31802
Published: July 2, 2025
CODESYS Gateway Server V2
Festo
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to only part of the specified password is being compared to the real CODESYS Gateway password. A remote attacker can specify a small password that matches the corresponding part of the longer real CODESYS Gateway password and perform authentication on the system.