CVE-2021-34585
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)
Description
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
Affected (28)
Products: Wago: 750 823 Firmware, 750 829 Firmware, 750 831 Firmware, 750 832 Firmware, 750 852 Firmware, 750 862 Firmware, 750 880 Firmware, 750 881 Firmware, 750 882 Firmware, 750 885 Firmware, 750 889 Firmware, 750 890 Firmware, 750 891 Firmware, 750 893 Firmware, 750 8202 Firmware, 750 8203 Firmware, 750 8204 Firmware, 750 8206 Firmware, 750 8207 Firmware, 750 8208 Firmware, 750 8210 Firmware, 750 8211 Firmware, 750 8212 Firmware, 750 8213 Firmware, 750 8214 Firmware, 750 8216 Firmware, 750 8217 Firmware · Codesys: Codesys
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 823 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 829 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 831 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 832 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 852 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 862 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 880 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 881 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 882 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 885 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw17 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 889 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 890 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 891 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw10 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 893 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8202 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8203 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8204 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8206 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8207 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8208 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8210 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8211 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8212 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8213 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8214 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8216 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before fw20 |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8217 | All versions |
References (4)
Source: info@cert.vde.com
Vendor Advisory
Source: info@cert.vde.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.