PT-2021-20567 · 3S Smart Software Solutions · Codesys

Tenable Research

·

Published

2021-10-26

·

Updated

2025-08-15

·

CVE-2021-34586

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: CODESYS V2 web server versions prior to V1.1.9.22
Description: The issue is related to crafted web server requests that may cause a Null pointer dereference in the CODESYS web server, potentially resulting in a denial-of-service condition.
Recommendations: For versions prior to V1.1.9.22, update to version V1.1.9.22 or later to resolve the issue.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2021-34586

Affected Products

Codesys