CVE-2021-34585

Severity
7.5HIGH
EPSS
0.5%
top 35.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateMay 24

Description

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages29 packages

NVDcodesys/codesys< 1.1.9.22
CVEListV5codesys/codesys_v2all web serversV1.1.9.22

🔴Vulnerability Details

2
GHSA
GHSA-rhmm-fwg9-r5m5: In the CODESYS V2 web server prior to V12022-05-24
CVEList
CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)2021-10-26
CVE-2021-34585 (HIGH CVSS 7.5) | In the CODESYS V2 web server prior | cvebase.io