CVE-2021-30186: Buffer Overflow
Published May 25, 2021
·Updated
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Affected Software
56 affected components
CODESYS PLCWinNT<2.4.7.55
CODESYS Runtime Toolkit<2.4.7.55
All of the following
WAGO 750-893 Firmware<fw08
WAGO 750-893
All of the following
WAGO 750-891 Firmware<fw08
WAGO 750-891
All of the following
WAGO 750-890 Firmware<fw08
WAGO 750-890
All of the following
WAGO 750-889 Firmware<fw15
WAGO 750-889
All of the following
WAGO 750-885 Firmware<fw15
WAGO 750-885
All of the following
WAGO 750-882 Firmware<fw15
WAGO 750-882
All of the following
WAGO 750-881 Firmware<fw15
WAGO 750-881
All of the following
WAGO 750-880 Firmware<fw16
WAGO 750-880
All of the following
WAGO 750-862 Firmware<fw08
WAGO 750-862
All of the following
WAGO 750-852 Firmware<fw15
WAGO 750-852
All of the following
WAGO 750-832 Firmware<fw08
WAGO 750-832
All of the following
WAGO 750-831 Firmware<fw15
WAGO 750-831
All of the following
WAGO 750-829 Firmware<fw15
WAGO 750-829
All of the following
WAGO 750-8202 Firmware<03.06.19_\(18\)
WAGO 750-8202
All of the following
WAGO 750-8203 Firmware<03.06.19_\(18\)
WAGO 750-8203
All of the following
WAGO 750-8204 Firmware<03.06.19_\(18\)
WAGO 750-8204
All of the following
WAGO 750-8206 Firmware<03.06.19_\(18\)
WAGO 750-8206
All of the following
WAGO 750-8207 Firmware<03.06.19_\(18\)
WAGO 750-8207
All of the following
WAGO 750-8208 Firmware<03.06.19_\(18\)
WAGO 750-8208
All of the following
WAGO 750-8210 Firmware<03.06.19_\(18\)
WAGO 750-8210
All of the following
WAGO 750-8211 Firmware<03.06.19_\(18\)
WAGO 750-8211
All of the following
WAGO 750-8212 Firmware<03.06.19_\(18\)
WAGO 750-8212
All of the following
WAGO 750-8213 Firmware<03.06.19_\(18\)
WAGO 750-8213
All of the following
WAGO 750-8214 Firmware<03.06.19_\(18\)
WAGO 750-8214
All of the following
WAGO 750-8216 Firmware<03.06.19_\(18\)
WAGO 750-8216
All of the following
WAGO 750-8217 Firmware<03.06.19_\(18\)
WAGO 750-8217
All of the following
WAGO 750-823 Firmware<fw08
WAGO 750-823
Event History
May 25, 2021
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-30186?
CVE-2021-30186 is a vulnerability in the CODESYS V2 runtime system SP before 2.4.7.55 that allows for a heap-based buffer overflow.
2
What is the severity of CVE-2021-30186?
The severity of CVE-2021-30186 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2021-30186?
CODESYS PLCWinNT versions up to and excluding 2.4.7.55 and Codesys Runtime Toolkit versions up to and excluding 2.4.7.55 are affected by CVE-2021-30186.
4
How can I fix CVE-2021-30186?
To fix CVE-2021-30186, it is recommended to upgrade the CODESYS V2 runtime system to version 2.4.7.55 or higher.
5
What are the Common Weakness Enumeration (CWE) IDs associated with CVE-2021-30186?
The CWE IDs associated with CVE-2021-30186 are CWE-119 and CWE-787.