CVE detail
CVE-2021-30195
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- 7th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 7th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has identified a new cyber espionage weapon called SharpPanda being used by a Chinese threat group, in an ongoing surveillance operation targeting a Southeast Asian government. The attack starts […]
vendorresearch.checkpoint.comJun 7, 2021, 3:24 PM Researchers have identified 10 vulnerabilities in CODESYS automation software for industrial control systems. Some are of high and critical severity. “The vendor rated some of these vulnerabilities as 10 out of 10, or extremely dangerous. Their exploitation can lead to remote command execution on PLC, which may disrupt technological processes and cause industrial accidents and economic losses,” said Vladimir Nazarov, Head of ICS Security at Positive Technologies. “The most notorious example of exploiting similar vulnerabilities … More →
newswww.helpnetsecurity.comJun 4, 2021, 6:55 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-30194CVSS 9.1 · Critical
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
- CVE-2021-30193CVSS 9.8 · Critical
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
- CVE-2021-30192CVSS 9.8 · Critical
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
1 mention - CVE-2021-30191CVSS 7.5 · High
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
- CVE-2021-30190CVSS 9.8 · Critical
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
- CVE-2021-30189CVSS 9.8 · Critical
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.