cbcvebase.
CVE-2021-34595
published 2021-10-26

CVE-2021-34595: A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions…

high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
codesyscodesys< 1.1.9.221.1.9.22
codesyscodesys_v2>= PLCWinNT < V2.4.7.56V2.4.7.56
codesyscodesys_v2>= Runtime Toolkit 32 bit full < V2.4.7.56V2.4.7.56
codesysplcwinnt< 2.4.7.562.4.7.56
codesysruntime_toolkit< 2.4.7.562.4.7.56
wago750-8202_firmware< fw20fw20
wago750-8203_firmware< fw20fw20
wago750-8204_firmware< fw20fw20
wago750-8206_firmware< fw20fw20
wago750-8207_firmware< fw20fw20
wago750-8208_firmware< fw20fw20
wago750-8210_firmware< fw20fw20
wago750-8211_firmware< fw20fw20
wago750-8212_firmware< fw20fw20
wago750-8213_firmware< fw20fw20
wago750-8214_firmware< fw20fw20
wago750-8216_firmware< fw20fw20
wago750-8217_firmware< fw20fw20
wago750-823_firmware< fw10fw10
wago750-829_firmware< fw17fw17
wago750-831_firmware< fw17fw17
wago750-832_firmware< fw10fw10
wago750-852_firmware< fw17fw17
wago750-862_firmware< fw10fw10
wago750-880_firmware< fw17fw17