CVE-2021-34584

CWE-126Buffer Over-read3 documents3 sources
Severity
9.1CRITICAL
EPSS
0.6%
top 30.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateMay 24

Description

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages29 packages

NVDcodesys/codesys< 1.1.9.22
CVEListV5codesys/codesys_v2all web serversV1.1.9.22

🔴Vulnerability Details

2
GHSA
GHSA-j5c2-6xq9-fj5m: Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the C2022-05-24
CVEList
CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS)2021-10-26
CVE-2021-34584 (CRITICAL CVSS 9.1) | Crafted web server requests can be | cvebase.io