CVE-2021-21867: High severity codesys development system vulnerability
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21867?
CVE-2021-21867 has a severity rating that indicates a risk of arbitrary command execution due to unsafe deserialization.
How do I fix CVE-2021-21867?
To fix CVE-2021-21867, upgrade to the latest version of CODESYS Development System beyond 3.5.17.
What versions of CODESYS are affected by CVE-2021-21867?
CVE-2021-21867 affects CODESYS Development System versions 3.5.16.0 and 3.5.17.0.
What type of vulnerability is CVE-2021-21867?
CVE-2021-21867 is categorized as an unsafe deserialization vulnerability.
Can CVE-2021-21867 be exploited remotely?
Yes, an attacker can exploit CVE-2021-21867 by providing a specially crafted file to the affected system.