cbcvebase.
CVE-2018-8836
published 2018-04-03

CVE-2018-8836: Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during…

PriorityP432medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
3.63%
88.3th percentile
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Affected

16 ranges
VendorProductVersion rangeFixed in
wago750-829_firmware<= 10
wago750-831_firmware<= 10
wago750-852_firmware<= 10
wago750-880_firmware<= 10
wago750-881_firmware<= 10
wago750-882_firmware<= 10
wago750-885_firmware<= 10
wago750-889_firmware<= 10
wagowago_750_series
wagowago_750_series
wagowago_750_series
wagowago_750_series
wagowago_750_series
wagowago_750_series
wagowago_750_series
wagowago_750_series

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.