CVE-2021-34583
Severity CVSS v4.0:
Pending analysis
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
26/10/2021
Last modified:
15/08/2025
Description
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-829:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-831:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-852:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-880_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-880:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-881_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16876&token=a3f1d937f95e7034879f4f2ea8e5a99b168256a7&download=
- https://www.tenable.com/security/research/tra-2021-47
- https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16876&token=a3f1d937f95e7034879f4f2ea8e5a99b168256a7&download=
- https://www.tenable.com/security/research/tra-2021-47



