CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
CVE-2021-34593

7.5HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
26 October 2021

What is CVE-2021-34593?

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Affected Version(s)

CODESYS V2 Runtime Toolkit 32 bit full

CODESYS V2 PLCWinNT

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Steffen Robertz and Gerhard Hechenberger from the SEC Consult Vulnerability Lab.
.