Vulnerabilities > CVE-2021-34593 - Improper Handling of Exceptional Conditions vulnerability in Codesys Plcwinnt and Runtime Toolkit

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
codesys
CWE-755

Summary

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Vulnerable Configurations

Part Description Count
Application
Codesys
4