cbcvebase.
CVE-2021-29242
published 2021-05-03

CVE-2021-29242: CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's…

high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

Affected

23 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_empc-a_imx6_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_iot2000_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_linux_arm_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_linux_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_pfc100_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_pfc200_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_plcnext_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_raspberry_pi_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_for_wago_touch_panels_600_sl>= 3.0 < 4.1.0.04.1.0.0
codesyscontrol_rte>= 3.0 < 3.5.17.03.5.17.0
codesyscontrol_runtime_system_toolkit>= 3.0 < 3.5.17.03.5.17.0
codesyscontrol_win>= 3.0 < 3.5.17.03.5.17.0
codesysedge_gateway>= 3.0 < 3.5.17.03.5.17.0
codesysedge_gateway>= 3.0 < 4.1.0.04.1.0.0
codesysembedded_target_visu_toolkit>= 3.0 < 3.5.17.03.5.17.0
codesysgateway>= 3.0 < 3.5.17.03.5.17.0
codesyshmi>= 3.0 < 3.5.17.03.5.17.0
codesysopc_server>= 3.0 < 3.5.17.03.5.17.0
codesysplchandler>= 3.0 < 3.5.17.03.5.17.0
codesysremote_target_visu_toolkit>= 3.0 < 3.5.17.03.5.17.0
codesyssafety_sil>= 3.0 < 3.5.17.03.5.17.0
codesyssimulation_runtime>= 3.0 < 3.5.17.03.5.17.0