First published: Wed Aug 04 2021(Updated: )
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CODESYS EtherNetIP | <4.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36765 is classified as a medium severity vulnerability.
CVE-2021-36765 affects CODESYS EtherNetIP versions prior to 4.1.0.0.
The fix for CVE-2021-36765 is to upgrade CODESYS EtherNetIP to version 4.1.0.0 or later.
CVE-2021-36765 can lead to a null pointer dereference that may cause application crashes.
There are currently no official workarounds available for CVE-2021-36765.