Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.82%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a…
ModificadaCrítica (9.1)2.5%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.
ModificadaCrítica (9.1)2.7%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to…
ModificadaAlta (7.8)1.9%—Wago E!cockpit11/3/202017/6/2026
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update,…
ModificadaAlta (7.8)1.1%—Wago E!cockpit11/3/202017/6/2026
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a newer firmware version is being installed.…
ModificadaAlta (7.2)4.2%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.
ModificadaAlta (7.2)4.2%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.
ModificadaAlta (7.2)4.6%—Wago Pfc200 Firmware11/3/202017/6/2026
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version…
ModificadaAlta (7.5)1.8%—Wago Pfc200 FirmwareWago Pfc100 Firmware11/3/202017/6/2026
The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default…
ModificadaMedia (5.3)1.0%—Wago Pfc200 FirmwareWago Pfc100 Firmware11/3/202017/6/2026
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200…
ModificadaAlta (7.5)2.3%—Wago Pfc200 FirmwareWago Pfc100 Firmware11/3/202017/6/2026
An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting…
ModificadaAlta (7.5)1.1%—Wago E!cockpit11/3/202017/6/2026
A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes passwords, configurations, and binaries being…
ModificadaMedia (5.5)0.34%—Wago E!cockpit11/3/202017/6/2026
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.
ModificadaCrítica (9.8)20%💥 PoCPoint-to-point Protocol Project Point-to-point ProtocolWago PFC FirmwareDebian LinuxCanonical Ubuntu Linux3/2/202017/6/2026
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
ModificadaCrítica (9.8)3.3%—Wago Pfc200 FirmwareWago Pfc100 Firmware8/1/202017/6/2026
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow,…
ModificadaCrítica (9.1)1.6%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A single packet can cause a denial of service and weaken credentials resulting in the default…
ModificadaCrítica (9.8)3.3%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code…
ModificadaCrítica (9.1)1.7%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an…
ModificadaCrítica (9.8)3.9%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer…
ModificadaMedia (5.3)1.6%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized…
ModificadaCrítica (9.8)4.5%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code…
ModificadaCrítica (9.1)1.6%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an…
ModificadaCrítica (9.8)3.3%—Wago PFC 200 FirmwareWago PFC 100 Firmware18/12/201917/6/2026
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow,…
ModificadaMedia (5.3)1.8%—Wago PFC Firmware19/10/201917/6/2026
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
ModificadaCrítica (9.8)2.7%—Wago 852-303 FirmwareWago 852-1305 FirmwareWago 852-1505 Firmware17/6/201917/6/2026
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
Orbitaley — Vulnerabilidades