CVE-2021-34593: CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34593?
CVE-2021-34593 is a vulnerability found in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, which can result in denial-of-service conditions.
What is the severity of CVE-2021-34593?
CVE-2021-34593 has a severity rating of 7.5 (high).
How does CVE-2021-34593 impact PLC programs?
CVE-2021-34593 can stop running PLC programs or cause memory leaks.
How can CVE-2021-34593 affect communication clients?
CVE-2021-34593 can block further communication clients from accessing the affected system.
Is there a fix available for CVE-2021-34593?
Yes, updating to versions V2.4.7.56 or above of CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT can fix the vulnerability.