CVE & CISA-KEV Catalog

CVE-2021-34595

HIGH
8.1
CVSS v3
NVD

Description

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

How to fix

Remediation Available
750-8202 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8203 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8204 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8206 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8207 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8208 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8210 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8211 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8212 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8213 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8214 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8216 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-8217 firmwareNVD
Affected:< fw20Fixed in:fw20CVE-2021-34595derived from NVD
750-823 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
750-829 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-831 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-832 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
750-852 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-862 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
750-880 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-881 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-882 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-885 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-889 firmwareNVD
Affected:< fw17Fixed in:fw17CVE-2021-34595derived from NVD
750-890 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
750-891 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
750-893 firmwareNVD
Affected:< fw10Fixed in:fw10CVE-2021-34595derived from NVD
codesysNVD
Affected:< 1.1.9.22Fixed in:1.1.9.22CVE-2021-34595derived from NVD
plcwinntNVD
Affected:< 2.4.7.56Fixed in:2.4.7.56CVE-2021-34595derived from NVD
runtime toolkitNVD
Affected:< 2.4.7.56Fixed in:2.4.7.56CVE-2021-34595derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Exploit Intelligence

0.85%probability of exploitation in 30 days
54thpercentile

Moderate risk: more likely to be exploited than 54% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2021-34595
CVE-2021-34595 severity badge

Markdown

[![CVE-2021-34595](https://tridentstack.com/cve/badge/CVE-2021-34595.svg)](https://tridentstack.com/cve/CVE-2021-34595)

HTML

<a href="https://tridentstack.com/cve/CVE-2021-34595"><img src="https://tridentstack.com/cve/badge/CVE-2021-34595.svg" alt="CVE-2021-34595"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-08-15.