NULL pointer dereference in CODESYS products - CVE-2021-29241

 

NULL pointer dereference in CODESYS products - CVE-2021-29241

Published: July 22, 2021


Vulnerability identifier: #VU55243
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29241
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the CmpGateway component. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

CODESYS Gateway V3
CODESYS Control V3 Runtime System Toolkit
CODESYS Development System
CODESYS Edge Gateway for Windows
CODESYS Edge Gateway for Linux

How to mitigate CVE-2021-29241

Install update from vendor's website.

CODESYS Gateway V3 - update to 3.5.17.0
CODESYS Control V3 Runtime System Toolkit - update to 3.5.17.0
CODESYS Development System - update to 3.5.17.0
CODESYS Edge Gateway for Windows - update to 3.5.17.0
CODESYS Edge Gateway for Linux - update to 4.1.0.0

External References

Related Security Bulletins