← Vulnerability feed

Vulnerability record · CVE-2021-21863 · published 5 August 2021

CVE-2021-21863: Codesys development system deserialization of untrusted data vulnerability

Codesys · Development System

A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

7.8 CVSS 3.1 High EPSS 1.2% · top 32.7% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score, v2 6.8
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9010Codesys control for beaglebone sl vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All …EPSS 1.9%8.8CVE-2023-3663Codesys development system vulnerabilityIn CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker t…EPSS 1.0%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.5CVE-2026-44469Codesys development system incorrect default permissions vulnerabilityThe affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A lo…EPSS 0.12%8.5CVE-2026-44468Codesys development system incorrect default permissions vulnerabilityThe affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local att…EPSS 0.14%8.1CVE-2022-22515Codesys control for beaglebone sl exposure of resource to wrong sphere vulnerabilityA remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read an…EPSS 1.1%7.8CVE-2022-22516Codesys control rte sl incorrect permission assignment vulnerabilityThe SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2021-21863), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.