CVE-2021-29242 - CVE House
Back to Database
Status published High CVE-2021-29242

CODESYS Control Runtime system before 3.5.17.0 has improper input validation....

Vulnerability Description

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-29242

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

control for beaglebone sl, control for empc-a\/imx6 sl, control for iot2000 sl, control for linux arm sl, control for linux sl, control for pfc100 sl, control for pfc200 sl, control for plcnext sl, control for raspberry pi sl, control for wago touch panels 600 sl, control rte, control runtime system toolkit, control win, edge gateway, embedded target visu toolkit, gateway, hmi, opc server, plchandler, remote target visu toolkit, safety sil, simulation runtime
Vulnerable Versions:
3.0

Timeline

Official Publish: May 3rd, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.