Wago
Wago 750-862 Firmware: vulnerabilidades y CVE
Wago 750-862 Firmware tiene 24 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1620 | Media (4.9) | 0.85% | — | 26 jun 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime. |
| CVE-2023-1619 | Media (4.9) | 0.79% | — | 26 jun 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet. |
| CVE-2023-1150 | Alta (7.5) | 0.93% | — | 26 jun 2023 | Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets. |
| CVE-2021-34596 | Media (6.5) | 0.85% | — | 26 oct 2021 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. |
| CVE-2021-34595 | Alta (8.1) | 0.88% | — | 26 oct 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or… |
| CVE-2021-34586 | Alta (7.5) | 14% | — | 26 oct 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. |
| CVE-2021-34585 | Alta (7.5) | 0.93% | — | 26 oct 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can… |
| CVE-2021-34584 | Crítica (9.1) | 1.1% | — | 26 oct 2021 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
| CVE-2021-34583 | Alta (7.5) | 8.4% | — | 26 oct 2021 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
| CVE-2021-34578 | Alta (8.1) | 0.96% | — | 31 ago 2021 | This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware… |
| CVE-2021-30195 | Alta (7.5) | 7.2% | — | 25 may 2021 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. |
| CVE-2021-30194 | Crítica (9.1) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. |
| CVE-2021-30193 | Crítica (9.8) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. |
| CVE-2021-30192 | Crítica (9.8) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. |
| CVE-2021-30191 | Alta (7.5) | 1.0% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
| CVE-2021-30190 | Crítica (9.8) | 1.4% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
| CVE-2021-30189 | Crítica (9.8) | 1.3% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. |
| CVE-2021-30188 | Crítica (9.8) | 1.3% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. |
| CVE-2021-30186 | Alta (7.5) | 7.4% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. |
| CVE-2021-30187 | Media (5.3) | 0.27% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. |
| CVE-2021-21001 | Media (6.5) | 1.1% | — | 24 may 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. |
| CVE-2021-21000 | Alta (7.5) | 1.0% | — | 24 may 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. |
| CVE-2020-12506 | Crítica (9.1) | 1.5% | — | 30 sept 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This… |
| CVE-2018-16210 | Media (6.1) | 0.95% | — | 12 oct 2018 | WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field. |