PT-2021-14804 · 3S Smart Software Solutions · Codesys Development System

Patrick Desantis

·

Published

2021-08-18

·

Updated

2022-07-29

·

CVE-2021-21867

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Development System versions 3.5.16 through 3.5.17
Description An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For versions 3.5.16 and 3.5.17, consider disabling the ObjectStream.ProfileByteArray functionality in the ObjectManager.plugin as a temporary workaround until a patch is available. Restrict access to the ObjectManager.plugin to minimize the risk of exploitation. Avoid using malicious files that can trigger this vulnerability until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21867

Affected Products

Codesys Development System