Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29242

24
FAUCET Score

CVE-2021-29242 is a high-severity improper input validation vulnerability affecting CODESYS Control Runtime systems prior to version 3.5.17.0. This flaw allows unauthenticated attackers to send specially crafted communication packets over the network, enabling them to manipulate the router's addressing scheme. Such manipulation could lead to the re-routing, addition, removal, or alteration of low-level communication packages, impacting confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and it is not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0, < 4.1.0.0CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
>= 3.0, < 4.1.0.0CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
>= 3.0, < 4.1.0.0CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
>= 3.0, < 4.1.0.0CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:*
>= 3.0, < 4.1.0.0CPE matchmatch criteria
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.07%
Probability of exploitation in next 30 days
EPSS Percentile
61.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0107 is in the 38th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted

Vendor Advisories (6)

capnprotollm-capnproto-015c99146afc5458HIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021
openwrtllm-openwrt-a9ad9c2761a5c26fHIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021
gcpllm-gcp-820dd444b9f4af78HIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021
kongllm-kong-ce9dd37d95525dc2HIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021
hanwhallm-hanwha-8e9929cc614a8a11HIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021
proxmoxllm-proxmox-a02fdcf0a410fc17HIGH

Vulnerability in the routing protocol of the PLC runtime

May 19, 2021

References

customers.codesys.com / index.php
Permissions RequiredVendor Advisory
customers.codesys.com / index.php
Vendor Advisory
codesys.com / security/security-reports.html
Vendor Advisory