7.5
CWE
252
Advisory Published
Updated

CVE-2021-34585: CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)

First published: Tue Oct 26 2021(Updated: )

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

Credit: info@cert.vde.com

Affected SoftwareAffected VersionHow to fix
CODESYS Development System<1.1.9.22

Remedy

CODESYS GmbH has released version V1.1.9.22 of the CODESYS V2 web server to solve the noted vulnerability issues. This version of the CODESYS V2 web server is also part of the CODESYS Development System setup version V2.3.9.68.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2021-34585?

    CVE-2021-34585 has been classified as a high severity vulnerability due to its potential to cause denial of service.

  • How do I fix CVE-2021-34585?

    To fix CVE-2021-34585, update the CODESYS V2 software to version 1.1.9.22 or later.

  • What impact does CVE-2021-34585 have on my system?

    CVE-2021-34585 can lead to a denial of service condition, rendering the web server non-responsive.

  • Is my version of CODESYS vulnerable to CVE-2021-34585?

    If you are using CODESYS versions prior to 1.1.9.22, your system is vulnerable to CVE-2021-34585.

  • What type of attack can exploit CVE-2021-34585?

    CVE-2021-34585 can be exploited through crafted web server requests that trigger a parser error.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203