← All CVEs

CVE-2021-34586

high · 7.5

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

7.5
CVSS
13.1%
EPSS (exploit prob.)
96th
EPSS percentile
2021-10-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-476

Affected products

VendorProductAffected versions
wago750-823_firmware< fw10
wago750-823all versions
wago750-829_firmware< fw17
wago750-829all versions
wago750-831_firmware< fw17
wago750-831all versions
wago750-832_firmware< fw10
wago750-832all versions
wago750-852_firmware< fw17
wago750-852all versions
wago750-862_firmware< fw10
wago750-862all versions
wago750-880_firmware< fw17
wago750-880all versions
wago750-881_firmware< fw17
wago750-881all versions
wago750-882_firmware< fw17
wago750-882all versions
wago750-885_firmware< fw17
wago750-885all versions
wago750-889_firmware< fw17
wago750-889all versions
wago750-890_firmware< fw10
wago750-890all versions
wago750-891_firmware< fw10
wago750-891all versions
wago750-893_firmware< fw10
wago750-893all versions
wago750-8202_firmware< fw20
wago750-8202all versions
wago750-8203_firmware< fw20
wago750-8203all versions
wago750-8204_firmware< fw20
wago750-8204all versions
wago750-8206_firmware< fw20
wago750-8206all versions
wago750-8207_firmware< fw20
wago750-8207all versions
wago750-8208_firmware< fw20
wago750-8208all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-34586