CVE-2021-34599

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
01/12/2021
Last modified:
28/07/2022

Description

Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codesys:git:*:*:*:*:*:*:*:* 1.1.0.0 (excluding)
cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:* 3.5.17.0 (excluding)