CVE-2021-36765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
04/08/2021
Last modified:
11/08/2021

Description

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codesys:ethernetip:*:*:*:*:*:*:*:* 4.1.0.0 (excluding)