In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/164716/CODESYS-2.4.7.0-Denial-Of-Service.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/165874/WAGO-750-8xxx-PLC-Denial-Of-Service-User-Enumeration.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2021/Oct/64 | Mailing List Third Party Advisory |
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16877&token=8faab0fc1e069f4edfca5d5aba8146139f67a175&download= | Vendor Advisory |
http://packetstormsecurity.com/files/164716/CODESYS-2.4.7.0-Denial-Of-Service.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/165874/WAGO-750-8xxx-PLC-Denial-Of-Service-User-Enumeration.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2021/Oct/64 | Mailing List Third Party Advisory |
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16877&token=8faab0fc1e069f4edfca5d5aba8146139f67a175&download= | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
|
History
15 Aug 2025, 20:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wago 750-8214 Firmware
Wago 750-8213 Firmware Wago 750-8216 Wago 750-8212 Firmware Wago 750-8202 Firmware Wago 750-8217 Firmware Wago 750-8206 Wago 750-8202 Wago 750-8203 Wago 750-8210 Firmware Wago 750-8214 Wago 750-8210 Wago 750-8206 Firmware Wago 750-8211 Wago 750-8208 Firmware Wago 750-8216 Firmware Wago 750-8217 Wago 750-8207 Firmware Wago 750-8204 Firmware Wago 750-8212 Wago 750-8213 Wago 750-8211 Firmware Wago 750-8204 Wago Wago 750-8208 Wago 750-8203 Firmware Wago 750-8207 |
|
CPE | cpe:2.3:h:wago:750-8212:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8207_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8202:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8210:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8213_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8207:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8213:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8204:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8216_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8208_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8211:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8212_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8204_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8206:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8203:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8216:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8203_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8211_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8217_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8214:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8210_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8214_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8217:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-8206_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-8208:-:*:*:*:*:*:*:* |
21 Nov 2024, 06:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/164716/CODESYS-2.4.7.0-Denial-Of-Service.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://packetstormsecurity.com/files/165874/WAGO-750-8xxx-PLC-Denial-Of-Service-User-Enumeration.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2021/Oct/64 - Mailing List, Third Party Advisory | |
References | () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=16877&token=8faab0fc1e069f4edfca5d5aba8146139f67a175&download= - Vendor Advisory |
Information
Published : 2021-10-26 10:15
Updated : 2025-08-15 20:25
NVD link : CVE-2021-34593
Mitre link : CVE-2021-34593
CVE.ORG link : CVE-2021-34593
JSON object : View
Products Affected
wago
- 750-8206
- 750-8216_firmware
- 750-8207_firmware
- 750-8202_firmware
- 750-8204_firmware
- 750-8203
- 750-8210_firmware
- 750-8210
- 750-8214_firmware
- 750-8216
- 750-8204
- 750-8208
- 750-8211_firmware
- 750-8206_firmware
- 750-8208_firmware
- 750-8212
- 750-8214
- 750-8213_firmware
- 750-8202
- 750-8217
- 750-8217_firmware
- 750-8212_firmware
- 750-8213
- 750-8203_firmware
- 750-8211
- 750-8207
codesys
- runtime_toolkit
- plcwinnt
CWE
CWE-755
Improper Handling of Exceptional Conditions