CVE-2021-34595 describes an out-of-bounds read or write vulnerability in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT versions prior to V2.4.7.56, triggered by a crafted request with invalid offsets. This vulnerability carries a high CVSS score of 8.1, indicating a network-exploitable flaw with low attack complexity that could lead to a denial-of-service or local memory overwrite, impacting confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< fw10CPE matchmatch criteria | cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:* | ||
< fw10CPE matchmatch criteria | cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* | ||
< fw17CPE matchmatch criteria | cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.