// For flags

CVE-2021-36763

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

En CODESYS V3 web server versiones anteriores a 3.5.17.10, los archivos o directorios son accesibles para las partes externas

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-16 CVE Reserved
  • 2021-08-03 CVE Published
  • 2024-04-18 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-552: Files or Directories Accessible to External Parties
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
beaglebone_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
empc-a\/imx6_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
iot2000_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
<= 4.2.0.0
Search vendor "Codesys" for product "Control" and version " <= 4.2.0.0"
linux_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
pfc100_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
pfc200_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
plcnext_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
raspberry_pi_sl
Affected
Codesys
Search vendor "Codesys"
Control
Search vendor "Codesys" for product "Control"
< 4.2.0.0
Search vendor "Codesys" for product "Control" and version " < 4.2.0.0"
wago_touch_panels_600_sl
Affected
Codesys
Search vendor "Codesys"
Control Rte
Search vendor "Codesys" for product "Control Rte"
< 3.5.17.10
Search vendor "Codesys" for product "Control Rte" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Control Rte
Search vendor "Codesys" for product "Control Rte"
< 3.5.17.10
Search vendor "Codesys" for product "Control Rte" and version " < 3.5.17.10"
beckhoff_cx
Affected
Codesys
Search vendor "Codesys"
Control Runtime System Toolkit
Search vendor "Codesys" for product "Control Runtime System Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Control Runtime System Toolkit" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Control Win Sl
Search vendor "Codesys" for product "Control Win Sl"
< 3.5.17.10
Search vendor "Codesys" for product "Control Win Sl" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Embedded Target Visu Toolkit
Search vendor "Codesys" for product "Embedded Target Visu Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Embedded Target Visu Toolkit" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Hmi
Search vendor "Codesys" for product "Hmi"
< 3.5.17.10
Search vendor "Codesys" for product "Hmi" and version " < 3.5.17.10"
-
Affected
Codesys
Search vendor "Codesys"
Remote Target Visu Toolkit
Search vendor "Codesys" for product "Remote Target Visu Toolkit"
< 3.5.17.10
Search vendor "Codesys" for product "Remote Target Visu Toolkit" and version " < 3.5.17.10"
-
Affected