Description
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16876&token=a3f1d937f95e7034879f4f2ea8e5a99b168256a7&download=
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2021-47
Scores
CVSS v3
7.5
EPSS
0.0069
EPSS Percentile
71.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-122
CWE-787
Status
published
Products (28)
codesys/codesys
< 1.1.9.22
wago/750-8202_firmware
< fw20
wago/750-8203_firmware
< fw20
wago/750-8204_firmware
< fw20
wago/750-8206_firmware
< fw20
wago/750-8207_firmware
< fw20
wago/750-8208_firmware
< fw20
wago/750-8210_firmware
< fw20
wago/750-8211_firmware
< fw20
wago/750-8212_firmware
< fw20
... and 18 more
Published
Oct 26, 2021
Tracked Since
Feb 18, 2026