CVE-2021-34585: high-severity vulnerability in CODESYS V2
CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The CODESYS V2 web server has a flaw where specially crafted requests can cause the server to crash, making it unavailable to users. This happens because the server doesn't properly check for errors when parsing these requests.
A remote attacker can send malformed HTTP requests to the CODESYS V2 web server (versions before V1.1.9.22) that trigger a parser error; the unchecked parser result leads to an invalid pointer dereference, causing a denial of service. No authentication or special privileges are required to exploit this vulnerability.
In the same product, most dangerous first.