CVE-2021-34566

Severity
9.1CRITICAL
EPSS
0.9%
top 24.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9

Description

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages55 packages

🔴Vulnerability Details

2
GHSA
GHSA-xcqq-8632-69xx: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash2022-11-09
CVEList
WAGO I/O-Check Service prone to Memory Overflow2022-11-09
CVE-2021-34566 (CRITICAL CVSS 9.1) | In WAGO I/O-Check Service in multip | cvebase.io