CVE-2021-34586 describes a Null pointer dereference vulnerability in the CODESYS V2 web server, specifically prior to version 1.1.9.22, impacting products like CODESYS and WAGO. This flaw allows an unauthenticated attacker to trigger a denial-of-service condition through specially crafted web server requests. With a CVSS score of 7.5 (HIGH), it presents a significant availability risk, though there is no known active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< fw10CPE matchmatch criteria | cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:* | ||
< fw10CPE matchmatch criteria | cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CODESYS V2 Web Server Multiple Vulnerabilities
Oct 26, 2021CODESYS V2 Web Server Multiple Vulnerabilities
Oct 26, 2021CODESYS V2 Web Server Multiple Vulnerabilities
Oct 26, 2021CODESYS V2 Web Server Multiple Vulnerabilities
Oct 26, 2021CODESYS V2 Web Server Multiple Vulnerabilities
Oct 26, 2021