CVE-2021-34596: CODESYS V2 runtime: Access of Uninitialized Pointer may result in denial-of-service
Published Oct 26, 2021
·Updated
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
Affected Software
57 affected components
CODESYS PLCWinNT<2.4.7.56
CODESYS Runtime Toolkit<2.4.7.56
All of the following
WAGO 750-823 Firmware<fw10
WAGO 750-823
All of the following
WAGO 750-829 Firmware<fw17
WAGO 750-829
All of the following
WAGO 750-831 Firmware<fw17
WAGO 750-831
All of the following
WAGO 750-832 Firmware<fw10
WAGO 750-832
All of the following
WAGO 750-852 Firmware<fw17
WAGO 750-852
All of the following
WAGO 750-862 Firmware<fw10
WAGO 750-862
All of the following
WAGO 750-880 Firmware<fw17
WAGO 750-880
All of the following
WAGO 750-881 Firmware<fw17
WAGO 750-881
All of the following
WAGO 750-882 Firmware<fw17
WAGO 750-882
All of the following
WAGO 750-885 Firmware<fw17
WAGO 750-885
All of the following
WAGO 750-889 Firmware<fw17
WAGO 750-889
All of the following
WAGO 750-890 Firmware<fw10
WAGO 750-890
All of the following
WAGO 750-891 Firmware<fw10
WAGO 750-891
All of the following
WAGO 750-893 Firmware<fw10
WAGO 750-893
All of the following
WAGO 750-8202 Firmware<fw20
WAGO 750-8202
All of the following
WAGO 750-8203 Firmware<fw20
WAGO 750-8203
All of the following
WAGO 750-8204 Firmware<fw20
WAGO 750-8204
All of the following
WAGO 750-8206 Firmware<fw20
WAGO 750-8206
All of the following
WAGO 750-8207 Firmware<fw20
WAGO 750-8207
All of the following
WAGO 750-8208 Firmware<fw20
WAGO 750-8208
All of the following
WAGO 750-8210 Firmware<fw20
WAGO 750-8210
All of the following
WAGO 750-8211 Firmware<fw20
WAGO 750-8211
All of the following
WAGO 750-8212 Firmware<fw20
WAGO 750-8212
All of the following
WAGO 750-8213 Firmware<fw20
WAGO 750-8213
All of the following
WAGO 750-8214 Firmware<fw20
WAGO 750-8214
All of the following
WAGO 750-8216 Firmware<fw20
WAGO 750-8216
All of the following
WAGO 750-8217 Firmware<fw20
WAGO 750-8217
CODESYS CODESYS<1.1.9.22
Remediation
Information
CODESYS GmbH has released the following product versions to solve the noted vulnerability issue for the affected CODESYS products:
* CODESYS Runtime Toolkit 32 bit full version V2.4.7.56
* CODESYS PLCWinNT version V2.4.7.56. This will also be part of the CODESYS Development System setup version V2.3.9.68.
Event History
Oct 26, 2021
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-34596.
2
What is the severity of CVE-2021-34596?
The severity of CVE-2021-34596 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2021-34596?
CODESYS PLCWinNT versions up to but not including 2.4.7.56 and Codesys Runtime Toolkit versions up to but not including 2.4.7.56 are affected by CVE-2021-34596.
4
What is the impact of CVE-2021-34596?
CVE-2021-34596 can result in a denial-of-service condition.
5
Where can I find more information about CVE-2021-34596?
You can find more information about CVE-2021-34596 at the following reference link: [link](https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16878&token=e5644ec405590e66aefa62304cb8632df9fc9e9c&download=).