IM
IronMonkey Threat Research

CVE-2021-30186 HIGH

Published: 2021-05-25 | Last Modified: 2025-08-15 | Status: Analyzed

Description

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

Additional Descriptions (1)

CODESYS V2 runtime system SP versiones anteriores a 2.4.7.55, presenta un Desbordamiento del Búfer en la región Heap de la memoria

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-787

Affected Products

Vendor Product Version Update Type
wago 750-893_firmware * <built-in method update of dict object at 0x7e611224f440> Operating System
wago 750-891_firmware * <built-in method update of dict object at 0x7e60ba2a6480> Operating System
wago 750-890_firmware * <built-in method update of dict object at 0x7e611224c4c0> Operating System
wago 750-889_firmware * <built-in method update of dict object at 0x7e611224dd40> Operating System
wago 750-885_firmware * <built-in method update of dict object at 0x7e611224c640> Operating System
wago 750-882_firmware * <built-in method update of dict object at 0x7e611224ec80> Operating System
wago 750-881_firmware * <built-in method update of dict object at 0x7e60ba2a7940> Operating System
wago 750-880_firmware * <built-in method update of dict object at 0x7e611224e680> Operating System
wago 750-862_firmware * <built-in method update of dict object at 0x7e611224e200> Operating System
wago 750-852_firmware * <built-in method update of dict object at 0x7e611224d100> Operating System
wago 750-832_firmware * <built-in method update of dict object at 0x7e611224c280> Operating System
wago 750-831_firmware * <built-in method update of dict object at 0x7e60a8a68140> Operating System
wago 750-829_firmware * <built-in method update of dict object at 0x7e60a8a69640> Operating System
wago 750-8202_firmware * <built-in method update of dict object at 0x7e60ba2a4840> Operating System
wago 750-8203_firmware * <built-in method update of dict object at 0x7e611224fe40> Operating System
wago 750-8204_firmware * <built-in method update of dict object at 0x7e611224d200> Operating System
wago 750-8206_firmware * <built-in method update of dict object at 0x7e60ba2a7340> Operating System
wago 750-8207_firmware * <built-in method update of dict object at 0x7e60a8a6b8c0> Operating System
wago 750-8208_firmware * <built-in method update of dict object at 0x7e60a8a69f00> Operating System
wago 750-8210_firmware * <built-in method update of dict object at 0x7e60a8a682c0> Operating System
wago 750-8211_firmware * <built-in method update of dict object at 0x7e611224e2c0> Operating System
wago 750-8212_firmware * <built-in method update of dict object at 0x7e60ba2a49c0> Operating System
wago 750-8213_firmware * <built-in method update of dict object at 0x7e60a8a6a5c0> Operating System
wago 750-8214_firmware * <built-in method update of dict object at 0x7e60ba2a5b00> Operating System
wago 750-8216_firmware * <built-in method update of dict object at 0x7e60a8a6bb00> Operating System
wago 750-8217_firmware * <built-in method update of dict object at 0x7e611224c500> Operating System
codesys plcwinnt * <built-in method update of dict object at 0x7e60a8a6b180> Application
codesys runtime_toolkit * <built-in method update of dict object at 0x7e60a8a6a740> Application
wago 750-823_firmware * <built-in method update of dict object at 0x7e60a8a6b500> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-893_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-893:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-891_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-891:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-890_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-890:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-889_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-889:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-885_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-885:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-882_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-882:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-881_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-881:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-880_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-880:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-852:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-831:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-829:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8202:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8203_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8203:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8204_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8204:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8206_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8206:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8207_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8207:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8208_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8208:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8210_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8210:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8211_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8211:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8212_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8212:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8213_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8213:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8214_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8214:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8216_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8216:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8217_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8217:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:codesys:plcwinnt:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:x86:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:*
Notification
Message here