CVE-2021-30192
published 2021-05-25CVE-2021-30192: CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.15%
63.3th percentile
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codesys | v2_web_server | < 1.1.9.20 | 1.1.9.20 |
| wago | 750-8202_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8203_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8204_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8206_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8207_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8208_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8210_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8211_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8212_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8213_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8214_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8216_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-8217_firmware | < 03.06.19_\(18\) | 03.06.19_\(18\) |
| wago | 750-823_firmware | < fw08 | fw08 |
| wago | 750-829_firmware | < fw15 | fw15 |
| wago | 750-831_firmware | < fw15 | fw15 |
| wago | 750-832_firmware | < fw08 | fw08 |
| wago | 750-852_firmware | < fw15 | fw15 |
| wago | 750-862_firmware | < fw08 | fw08 |
| wago | 750-880_firmware | < fw16 | fw16 |
| wago | 750-881_firmware | < fw15 | fw15 |
| wago | 750-882_firmware | < fw15 | fw15 |
| wago | 750-885_firmware | < fw15 | fw15 |
| wago | 750-889_firmware | < fw15 | fw15 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8j4-8jwg-mc3j: CODESYS V2 Web-Server before 1
ghsa_unreviewed·2022-05-24
CVE-2021-30192 [CRITICAL] CWE-863 GHSA-m8j4-8jwg-mc3j: CODESYS V2 Web-Server before 1
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
CISA ICS
CODESYS V2 web server
cisa_ics·2021-06-22·CVSS 9.8
[CRITICAL] CODESYS V2 web server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
CODESYS V2 web server
Last RevisedJune 22, 2021
Alert CodeICSA-21-173-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: CODESYS, GmbH
- Equipment: CODESYS V2 web server
- Vulnerabilities: Stack-based Buffer Overflow, Improper Access Control, Buffer Copy without Checking Size of Input, Improperly Implemented Security Check, Out-of-bounds Write, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to read or write arbitrary memory or files in the CODESYS Contro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://customers.codesys.com/index.phphttps://customers.codesys.com/index.php?eID=dumpFile&t=f&f=14726&token=553da5d11234bbe1ceed59969d419a71bb8c8747&download=https://customers.codesys.com/index.phphttps://customers.codesys.com/index.php?eID=dumpFile&t=f&f=14726&token=553da5d11234bbe1ceed59969d419a71bb8c8747&download=
2021-05-25
Published