ID:8209 - Exploit for Improper access control in CODESYS V2 web server - CVE-2021-30190
Published: August 3, 2022
CODESYS V2 web server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the user management. A remote attacker can use a specially crafted web server request to bypass user management and read or write values on the PLC without authentication.