7.5

CVE-2021-29242

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

Data is provided by the National Vulnerability Database (NVD)
CodesysControl For Beaglebone Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Empc-a/imx6 Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Iot2000 Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Linux Arm Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Linux Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Pfc100 Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Pfc200 Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Plcnext Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Raspberry Pi Sl Version >= 3.0 < 4.1.0.0
CodesysControl For Wago Touch Panels 600 Sl Version >= 3.0 < 4.1.0.0
CodesysControl Rte Version >= 3.0 < 3.5.17.0
CodesysControl Rte SwPlatformbeckhoff_cx Version >= 3.0 < 3.5.17.0
CodesysControl Runtime System Toolkit Version >= 3.0 < 3.5.17.0
CodesysControl Win Version >= 3.0 < 3.5.17.0
CodesysEdge Gateway SwPlatformwindows Version >= 3.0 < 3.5.17.0
CodesysEdge Gateway SwPlatformlinux Version >= 3.0 < 4.1.0.0
CodesysEmbedded Target Visu Toolkit Version >= 3.0 < 3.5.17.0
CodesysGateway Version >= 3.0 < 3.5.17.0
CodesysHmi Version >= 3.0 < 3.5.17.0
CodesysOpc Server Version >= 3.0 < 3.5.17.0
CodesysPlchandler Version >= 3.0 < 3.5.17.0
CodesysRemote Target Visu Toolkit Version >= 3.0 < 3.5.17.0
CodesysSafety Sil Version >= 3.0 < 3.5.17.0
CodesysSimulation Runtime Version >= 3.0 < 3.5.17.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.44% 0.622
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.