CVE-2021-34585: CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34585?
CVE-2021-34585 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2021-34585?
To fix CVE-2021-34585, update the CODESYS V2 software to version 1.1.9.22 or later.
What impact does CVE-2021-34585 have on my system?
CVE-2021-34585 can lead to a denial of service condition, rendering the web server non-responsive.
Is my version of CODESYS vulnerable to CVE-2021-34585?
If you are using CODESYS versions prior to 1.1.9.22, your system is vulnerable to CVE-2021-34585.
What type of attack can exploit CVE-2021-34585?
CVE-2021-34585 can be exploited through crafted web server requests that trigger a parser error.