Severity
7.5HIGH
EPSS
0.7%
top 28.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateMay 24

Description

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages29 packages

NVDcodesys/codesys< 1.1.9.22
CVEListV5codesys/codesys_v2all web serversV1.1.9.22

🔴Vulnerability Details

2
GHSA
GHSA-rx79-rgx5-5gqx: Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CO2022-05-24
CVEList
CODESYS V2 web server: crafted requests could trigger a heap-based buffer overflow (DoS)2021-10-26
CVE-2021-34583 (HIGH CVSS 7.5) | Crafted web server requests may cau | cvebase.io