This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
References
Link | Resource |
---|---|
https://cert.vde.com/en-us/advisories/vde-2020-044 | Third Party Advisory |
https://cert.vde.com/en-us/advisories/vde-2020-044 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
History
21 Nov 2024, 06:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.vde.com/en-us/advisories/vde-2020-044 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 9.8 |
08 Sep 2021, 16:02
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.1 |
CPE | cpe:2.3:o:wago:750-890\/040-000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-002:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-001_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-893_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-002_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-862_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-363_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-891:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-000:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-862:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/025-001:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-362_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-832:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-363:-:*:*:*:*:*:*:* cpe:2.3:o:wago:750-891_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-832\/000-002_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:wago:750-890\/025-000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:wago:750-832\/000-002:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-890\/040-000:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-893:-:*:*:*:*:*:*:* cpe:2.3:h:wago:750-362:-:*:*:*:*:*:*:* |
|
References | (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2020-044 - Third Party Advisory |
31 Aug 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-31 11:15
Updated : 2024-11-21 06:10
NVD link : CVE-2021-34578
Mitre link : CVE-2021-34578
CVE.ORG link : CVE-2021-34578
JSON object : View
Products Affected
wago
- 750-890\/025-000_firmware
- 750-832_firmware
- 750-862_firmware
- 750-362_firmware
- 750-832
- 750-890\/040-000
- 750-862
- 750-823_firmware
- 750-890\/025-002
- 750-890\/025-002_firmware
- 750-893_firmware
- 750-823
- 750-832\/000-002
- 750-893
- 750-890\/025-001_firmware
- 750-891
- 750-362
- 750-832\/000-002_firmware
- 750-363
- 750-891_firmware
- 750-363_firmware
- 750-890\/025-001
- 750-890\/025-000
- 750-890\/040-000_firmware
CWE
CWE-287
Improper Authentication