5
CVSSv2

CVE-2021-34593

Published: 26/10/2021 Updated: 12/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codesys plcwinnt

codesys runtime toolkit

Exploits

WAGO 750-8xxx PLC versions prior to Firmware 20 Patch 1 (v030808) suffer from denial of service and user enumeration vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20211028-0 :: Denial of Service in CODESYS V2 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fr ...