CVE-2021-34595
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/10/2021
Last modified:
15/08/2025
Description
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-829:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-831:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-852:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:* | fw10 (excluding) | |
| cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-880_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) | |
| cpe:2.3:h:wago:750-880:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-881_firmware:*:*:*:*:*:*:*:* | fw17 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



