Description
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://customers.codesys.com/index.php
Vendor Advisory x_refsource_misc
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=14726&token=553da5d11234bbe1ceed59969d419a71bb8c8747&download=
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
61.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-120
Status
published
Products (28)
codesys/v2_web_server
< 1.1.9.20
wago/750-8202_firmware
< 03.06.19_\(18\)
wago/750-8203_firmware
< 03.06.19_\(18\)
wago/750-8204_firmware
< 03.06.19_\(18\)
wago/750-8206_firmware
< 03.06.19_\(18\)
wago/750-8207_firmware
< 03.06.19_\(18\)
wago/750-8208_firmware
< 03.06.19_\(18\)
wago/750-8210_firmware
< 03.06.19_\(18\)
wago/750-8211_firmware
< 03.06.19_\(18\)
wago/750-8212_firmware
< 03.06.19_\(18\)
... and 18 more
Published
May 25, 2021
Tracked Since
Feb 18, 2026