cbcvebase.
CVE-2021-34596
published 2021-10-26

CVE-2021-34596: A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56…

PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.83%
53.4th percentile
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
codesyscodesys< 1.1.9.221.1.9.22
codesyscodesys_v2>= PLCWinNT < V2.4.7.56V2.4.7.56
codesyscodesys_v2>= Runtime Toolkit 32 bit full < V2.4.7.56V2.4.7.56
codesysplcwinnt< 2.4.7.562.4.7.56
codesysruntime_toolkit< 2.4.7.562.4.7.56
wago750-8202_firmware< fw20fw20
wago750-8203_firmware< fw20fw20
wago750-8204_firmware< fw20fw20
wago750-8206_firmware< fw20fw20
wago750-8207_firmware< fw20fw20
wago750-8208_firmware< fw20fw20
wago750-8210_firmware< fw20fw20
wago750-8211_firmware< fw20fw20
wago750-8212_firmware< fw20fw20
wago750-8213_firmware< fw20fw20
wago750-8214_firmware< fw20fw20
wago750-8216_firmware< fw20fw20
wago750-8217_firmware< fw20fw20
wago750-823_firmware< fw10fw10
wago750-829_firmware< fw17fw17
wago750-831_firmware< fw17fw17
wago750-832_firmware< fw10fw10
wago750-852_firmware< fw17fw17
wago750-862_firmware< fw10fw10
wago750-880_firmware< fw17fw17

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.