CVE-2021-34595: high-severity vulnerability in CODESYS V2
CODESYS V2 runtime: out-of-bounds read or write access may result in denial-of-service
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A specially crafted request with invalid offsets can cause the CODESYS V2 Runtime to read or write outside its allowed memory boundaries, crashing the system or corrupting data on the affected machine.
Out-of-bounds memory access vulnerability in CODESYS V2 Runtime Toolkit 32 Bit and PLCWinNT (pre-V2.4.7.56) triggered by malformed requests with invalid offsets; attackers with local access can trigger denial-of-service or overwrite sensitive memory regions. The vulnerability requires crafting specific requests that bypass bounds validation during memory operations.
In the same product, most dangerous first.