ID:9335 - Exploit for Improper access control in CODESYS V2 web server - CVE-2021-30190
Published: September 18, 2023
CODESYS V2 web server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the user management. A remote attacker can use a specially crafted web server request to bypass user management and read or write values on the PLC without authentication.