cbcvebase.
CVE-2021-34585
published 2021-10-26

CVE-2021-34585: In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
codesyscodesys< 1.1.9.221.1.9.22
codesyscodesys_v2>= all web servers < V1.1.9.22V1.1.9.22
wago750-8202_firmware< fw20fw20
wago750-8203_firmware< fw20fw20
wago750-8204_firmware< fw20fw20
wago750-8206_firmware< fw20fw20
wago750-8207_firmware< fw20fw20
wago750-8208_firmware< fw20fw20
wago750-8210_firmware< fw20fw20
wago750-8211_firmware< fw20fw20
wago750-8212_firmware< fw20fw20
wago750-8213_firmware< fw20fw20
wago750-8214_firmware< fw20fw20
wago750-8216_firmware< fw20fw20
wago750-8217_firmware< fw20fw20
wago750-823_firmware< fw10fw10
wago750-829_firmware< fw17fw17
wago750-831_firmware< fw17fw17
wago750-832_firmware< fw10fw10
wago750-852_firmware< fw17fw17
wago750-862_firmware< fw10fw10
wago750-880_firmware< fw17fw17
wago750-881_firmware< fw17fw17
wago750-882_firmware< fw17fw17
wago750-885_firmware< fw17fw17