CVE-2021-29242: Input Validation
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29242?
CVE-2021-29242 is a vulnerability in the CODESYS Control Runtime system before version 3.5.17.0 that has improper input validation.
How does CVE-2021-29242 impact the system?
CVE-2021-29242 allows attackers to send crafted communication packets to change the router's addressing scheme and may re-route, add, remove, or change low-level communication packages.
Which software versions are affected by CVE-2021-29242?
CODESYS Control Runtime system versions before 3.5.17.0 are affected by CVE-2021-29242.
What is the severity of CVE-2021-29242?
CVE-2021-29242 has a severity rating of 7.3 (high).
How can I mitigate CVE-2021-29242?
To mitigate CVE-2021-29242, it is recommended to update the CODESYS Control Runtime system to version 3.5.17.0 or higher.