Wago
Wago 750-889 Firmware: vulnerabilidades y CVE
Wago 750-889 Firmware tiene 26 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses0
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1620 | Media (4.9) | 0.85% | — | 26 jun 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime. |
| CVE-2023-1619 | Media (4.9) | 0.79% | — | 26 jun 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet. |
| CVE-2021-34596 | Media (6.5) | 0.85% | — | 26 oct 2021 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. |
| CVE-2021-34595 | Alta (8.1) | 0.88% | — | 26 oct 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or… |
| CVE-2021-34586 | Alta (7.5) | 14% | — | 26 oct 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. |
| CVE-2021-34585 | Alta (7.5) | 0.93% | — | 26 oct 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can… |
| CVE-2021-34584 | Crítica (9.1) | 1.1% | — | 26 oct 2021 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
| CVE-2021-34583 | Alta (7.5) | 8.4% | — | 26 oct 2021 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
| CVE-2021-34581 | Alta (7.5) | 1.0% | — | 31 ago 2021 | Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to… |
| CVE-2021-30195 | Alta (7.5) | 7.2% | — | 25 may 2021 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. |
| CVE-2021-30194 | Crítica (9.1) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. |
| CVE-2021-30193 | Crítica (9.8) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. |
| CVE-2021-30192 | Crítica (9.8) | 1.2% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. |
| CVE-2021-30191 | Alta (7.5) | 1.0% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
| CVE-2021-30190 | Crítica (9.8) | 1.4% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
| CVE-2021-30189 | Crítica (9.8) | 1.3% | — | 25 may 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. |
| CVE-2021-30188 | Crítica (9.8) | 1.3% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. |
| CVE-2021-30186 | Alta (7.5) | 7.4% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. |
| CVE-2021-30187 | Media (5.3) | 0.27% | — | 25 may 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. |
| CVE-2021-21001 | Media (6.5) | 1.1% | — | 24 may 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. |
| CVE-2021-21000 | Alta (7.5) | 1.0% | — | 24 may 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. |
| CVE-2020-12516 | Alta (7.5) | 1.9% | — | 10 dic 2020 | Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack. |
| CVE-2020-12505 | Crítica (9.1) | 1.2% | — | 30 sept 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx,… |
| CVE-2019-10712 | Crítica (9.8) | 2.8% | — | 7 may 2019 | The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has… |
| CVE-2018-16210 | Media (6.1) | 0.95% | — | 12 oct 2018 | WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field. |
| CVE-2018-8836 | Media (5.3) | 3.7% | — | 3 abr 2018 | Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with… |