#VU54325 Improper access control in CODESYS V2 web server - CVE-2021-30190
Published: June 23, 2021 / Updated: September 18, 2023
CODESYS V2 web server
CODESYS
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the user management. A remote attacker can use a specially crafted web server request to bypass user management and read or write values on the PLC without authentication.