← Back

CVE-2021-29242

nvd nist
Published: May 3, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

Affected (24)

22 products
Control For Beaglebone Sl
Control For Empc A/imx6 Sl
Control For Iot2000 Sl
Control For Linux Arm Sl
Control For Linux Sl
Control For Pfc100 Sl
Control For Pfc200 Sl
Control For Plcnext Sl
Control For Raspberry Pi Sl
Control Rte
Control Runtime System Toolkit
Control Win
Edge Gateway
Embedded Target Visu Toolkit
Gateway
Hmi
Opc Server
Plchandler
Remote Target Visu Toolkit
Safety Sil
Simulation Runtime
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
From 3.0 to 4.1.0.0
Codesys
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
Codesys
From 3.0 to 4.1.0.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0
From 3.0 to 3.5.17.0

References (6)

Source: cve@mitre.org
Permissions RequiredVendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.