← Vulnerability feed

Vulnerability record · CVE-2021-33486 · published 3 August 2021

CVE-2021-33486: Codesys runtime toolkit vulnerability

Codesys · Runtime Toolkit

All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.

7.5 CVSS 3.1 High EPSS 0.96% · top 39.9% CWE-755 · CWE-755
7.5CVSS 3.1 base score, v2 5.0
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33486 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31806Codesys plcwinnt insecure default initialization vulnerabilityIn CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no informatio…EPSS 1.2%8.8CVE-2023-6357Codesys control for beaglebone sl os command injection vulnerabilityA low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the…EPSS 0.96%8.8CVE-2022-4224Codesys control for beaglebone sl insecure default initialization vulnerabilityIn multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files…EPSS 0.88%8.8CVE-2022-32143Codesys plcwinnt vulnerabilityIn multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the P…EPSS 1.2%8.8CVE-2022-32137Codesys plcwinnt heap-based buffer overflow vulnerabilityIn multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a deni…EPSS 1.4%8.8CVE-2022-32138Codesys plcwinnt vulnerabilityIn multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service co…EPSS 1.2%8.8CVE-2019-9013Codesys control for beaglebone sl broken cryptographic algorithm vulnerabilityAn issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials bein…EPSS 0.28%8.1CVE-2022-32142Codesys plcwinnt vulnerabilityMultiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-33486), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.