Improper Input Validation in CODESYS Control Runtime System
CVE-2021-29242

7.3HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
3 May 2021

What is CVE-2021-29242?

CODESYS Control Runtime system versions earlier than 3.5.17.0 are affected by an improper input validation vulnerability. This flaw allows attackers to send specially crafted communication packets that can alter the router's addressing scheme, potentially enabling them to reroute, add, remove, or modify low-level communication packages undetected. This vulnerability poses significant risks to system integrity and communication reliability.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.