CVE-2021-34593: high-severity vulnerability in CODESYS V2
CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The CODESYS V2 Runtime allows anyone to send specially crafted invalid requests that can crash the system, stop running programs, or prevent other users from connecting to the programmable logic controller (PLC).
Unauthenticated remote attackers can send malformed requests to CODESYS V2 Runtime (versions before V2.4.7.56) to trigger denial-of-service conditions including process termination, memory exhaustion, and connection blocking. The vulnerability requires network access but no authentication, with high impact on PLC availability.
In the same product, most dangerous first.