IM
IronMonkey Threat Research

CVE-2021-30188 CRITICAL

Published: 2021-05-25 | Last Modified: 2025-08-15 | Status: Analyzed

Description

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

Additional Descriptions (1)

CODESYS V2 runtime system SP versiones anteriores a 2.4.7.55, presenta un Desbordamiento del Búfer en la región stack de la memoria

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.9

Base Score: 7.5 (HIGH)

AV:N/AC:L/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-787

Affected Products

Vendor Product Version Update Type
wago 750-893_firmware * <built-in method update of dict object at 0x7e60ba04df80> Operating System
wago 750-891_firmware * <built-in method update of dict object at 0x7e60ba04df00> Operating System
wago 750-890_firmware * <built-in method update of dict object at 0x7e60ba04e900> Operating System
wago 750-889_firmware * <built-in method update of dict object at 0x7e60ba04d3c0> Operating System
wago 750-885_firmware * <built-in method update of dict object at 0x7e60ba04e000> Operating System
wago 750-882_firmware * <built-in method update of dict object at 0x7e60ba04dfc0> Operating System
wago 750-881_firmware * <built-in method update of dict object at 0x7e60ba04d080> Operating System
wago 750-880_firmware * <built-in method update of dict object at 0x7e60bbef4680> Operating System
wago 750-862_firmware * <built-in method update of dict object at 0x7e60bbef52c0> Operating System
wago 750-852_firmware * <built-in method update of dict object at 0x7e60ba04d0c0> Operating System
wago 750-832_firmware * <built-in method update of dict object at 0x7e60ba04c780> Operating System
wago 750-831_firmware * <built-in method update of dict object at 0x7e60ba04c180> Operating System
wago 750-829_firmware * <built-in method update of dict object at 0x7e60ba04d700> Operating System
wago 750-8202_firmware * <built-in method update of dict object at 0x7e611116c840> Operating System
wago 750-8203_firmware * <built-in method update of dict object at 0x7e60ba04cb00> Operating System
wago 750-8204_firmware * <built-in method update of dict object at 0x7e60bbef62c0> Operating System
wago 750-8206_firmware * <built-in method update of dict object at 0x7e60ba04ce80> Operating System
wago 750-8207_firmware * <built-in method update of dict object at 0x7e60ba04f240> Operating System
wago 750-8208_firmware * <built-in method update of dict object at 0x7e611116e2c0> Operating System
wago 750-8210_firmware * <built-in method update of dict object at 0x7e60ba04d2c0> Operating System
wago 750-8211_firmware * <built-in method update of dict object at 0x7e60ba04e080> Operating System
wago 750-8212_firmware * <built-in method update of dict object at 0x7e60ba04d840> Operating System
wago 750-8213_firmware * <built-in method update of dict object at 0x7e60bbef6040> Operating System
wago 750-8214_firmware * <built-in method update of dict object at 0x7e60ba04dd40> Operating System
wago 750-8216_firmware * <built-in method update of dict object at 0x7e60bbef4980> Operating System
wago 750-8217_firmware * <built-in method update of dict object at 0x7e60ba04cd00> Operating System
codesys v2_runtime_system_sp * <built-in method update of dict object at 0x7e60ba04c300> Application
wago 750-823_firmware * <built-in method update of dict object at 0x7e60b9fb7140> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-893_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-893:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-891_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-891:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-890_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-890:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-889_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-889:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-885_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-885:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-882_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-882:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-881_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-881:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-880_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-880:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-852:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-831:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-829:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8202:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8203_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8203:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8204_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8204:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8206_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8206:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8207_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8207:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8208_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8208:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8210_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8210:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8211_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8211:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8212_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8212:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8213_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8213:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8214_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8214:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8216_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8216:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-8217_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-8217:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:codesys:v2_runtime_system_sp:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:*
Notification
Message here