This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
                
            References
                    | Link | Resource | 
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2020-044 | Third Party Advisory | 
| https://cert.vde.com/en-us/advisories/vde-2020-044 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
Configuration 5 (hide)
| AND | 
 
 | 
Configuration 6 (hide)
| AND | 
 
 | 
Configuration 7 (hide)
| AND | 
 
 | 
Configuration 8 (hide)
| AND | 
 
 | 
Configuration 9 (hide)
| AND | 
 
 | 
Configuration 10 (hide)
| AND | 
 
 | 
Configuration 11 (hide)
| AND | 
 
 | 
Configuration 12 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 06:10
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://cert.vde.com/en-us/advisories/vde-2020-044 - Third Party Advisory | |
| CVSS | v2 : v3 : | v2 : 6.8 v3 : 9.8 | 
08 Sep 2021, 16:02
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : 6.8 v3 : 8.1 | 
| CPE | cpe:2.3:o:wago:750-890\/040-000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-002:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-001_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-893_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-002_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-363_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-891:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-000:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-001:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-362_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-363:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-891_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-832\/000-002_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-832\/000-002:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/040-000:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-893:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-362:-:*:*:*:*:*:*:* | |
| References | (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2020-044 - Third Party Advisory | 
31 Aug 2021, 11:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-08-31 11:15
Updated : 2024-11-21 06:10
NVD link : CVE-2021-34578
Mitre link : CVE-2021-34578
CVE.ORG link : CVE-2021-34578
JSON object : View
Products Affected
                wago
- 750-891
- 750-890\/025-000_firmware
- 750-363_firmware
- 750-862_firmware
- 750-890\/040-000_firmware
- 750-890\/025-001_firmware
- 750-363
- 750-890\/025-000
- 750-891_firmware
- 750-890\/025-002_firmware
- 750-893_firmware
- 750-362_firmware
- 750-890\/025-001
- 750-832
- 750-832_firmware
- 750-832\/000-002_firmware
- 750-832\/000-002
- 750-862
- 750-823
- 750-890\/025-002
- 750-823_firmware
- 750-362
- 750-893
- 750-890\/040-000
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
