CVE-2021-34583
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
Affected (28)
Products: Wago: 750 8214 Firmware, 750 8216 Firmware, 750 8217 Firmware, 750 8213 Firmware, 750 8212 Firmware, 750 8211 Firmware, 750 8210 Firmware, 750 8208 Firmware, 750 8207 Firmware, 750 8206 Firmware, 750 8204 Firmware, 750 8203 Firmware, 750 8202 Firmware, 750 893 Firmware, 750 891 Firmware, 750 890 Firmware, 750 889 Firmware, 750 885 Firmware, 750 882 Firmware, 750 881 Firmware, 750 880 Firmware, 750 862 Firmware, 750 852 Firmware, 750 832 Firmware, 750 831 Firmware, 750 829 Firmware, 750 823 Firmware · Codesys: Codesys
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8214 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8216 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8217 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8213 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8212 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8211 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8210 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8208 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8207 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8206 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8204 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8203 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8202 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 893 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 891 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 890 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 889 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 885 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 882 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 881 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 880 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 862 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 852 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 832 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 831 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 829 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 823 | All versions |
Related CWEs
CWE-122
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (4)
Source: info@cert.vde.com
Vendor Advisory
Source: info@cert.vde.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.