PT-2021-7779 · 3S Smart Software Solutions · Codesys Development System

Published

2021-08-05

·

Updated

2022-09-30

·

CVE-2021-21863

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Development System versions 3.5.16 through 3.5.17
Description A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality. This issue is related to deficiencies in the deserialization mechanism, allowing an attacker to execute arbitrary commands by providing a specially crafted file. The vulnerability can be triggered when a malicious file is used, leading to potential command execution.
Recommendations For versions 3.5.16 and 3.5.17, consider disabling the Profile.FromFile() function until a patch is available to prevent exploitation. Restrict access to files that could be used to trigger this vulnerability to minimize the risk of arbitrary command execution.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-02777
CVE-2021-21863

Affected Products

Codesys Development System