// For flags

CVE-2021-33485

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

CODESYS Control Runtime system versiones anteriores a 3.5.17.10, presenta un Desbordamiento de Buffer en la regiĆ³n Heap de la memoria

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-21 CVE Reserved
  • 2021-08-03 CVE Published
  • 2024-04-18 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
beaglebone_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
empc-a\/imx6_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
iot2000_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
<= 4.2.0.0
Search vendor "Codesys" for product "Control" and version " <= 4.2.0.0"
linux_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
pfc100_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
pfc200_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
plcnext_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
raspberry_pi_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
wago_touch_panels_600_sl
Affected
Codesys
Search vendor "Codesys"
Control Rte
Search vendor "Codesys" for product "Control Rte"
< 3.5.17.10
Search vendor "Codesys" for product "Control Rte" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Control Rte
Search vendor "Codesys" for product "Control Rte"
< 3.5.17.10
Search vendor "Codesys" for product "Control Rte" and version " < 3.5.17.10"
beckhoff_cx
Affected
Codesys
Search vendor "Codesys"
Control Runtime System Toolkit
Search vendor "Codesys" for product "Control Runtime System Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Control Runtime System Toolkit" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Control Win Sl
Search vendor "Codesys" for product "Control Win Sl"
< 3.5.17.10
Search vendor "Codesys" for product "Control Win Sl" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Embedded Target Visu Toolkit
Search vendor "Codesys" for product "Embedded Target Visu Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Embedded Target Visu Toolkit" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Hmi
Search vendor "Codesys" for product "Hmi"
< 3.5.17.10
Search vendor "Codesys" for product "Hmi" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Remote Target Visu Toolkit
Search vendor "Codesys" for product "Remote Target Visu Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Remote Target Visu Toolkit" and version " < 3.5.17.10"
-
Affected