CVE-2019-10712
published 2019-05-07CVE-2019-10712: The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x…
PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.76%
84.6th percentile
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | 750-330_firmware | < 14 | 14 |
| wago | 750-352_firmware | < 14 | 14 |
| wago | 750-829_firmware | < 14 | 14 |
| wago | 750-830_firmware | < 06 | 06 |
| wago | 750-831_firmware | < 14 | 14 |
| wago | 750-849_firmware | < 08 | 08 |
| wago | 750-852_firmware | < 14 | 14 |
| wago | 750-871_firmware | < 11 | 11 |
| wago | 750-872_firmware | < 07 | 07 |
| wago | 750-873_firmware | < 07 | 07 |
| wago | 750-880_firmware | < 14 | 14 |
| wago | 750-881_firmware | < 14 | 14 |
| wago | 750-882_firmware | < 14 | 14 |
| wago | 750-884_firmware | < 14 | 14 |
| wago | 750-885_firmware | < 14 | 14 |
| wago | 750-889_firmware | < 14 | 14 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability involves undocumented hard-coded credentials on the WAGO Web-GUI that allow unauthenticated remote access with administrator privileges; monitor for unexpected authenticated sessions to the web-based management interface on affected WAGO 750-88x and 750-87x devices, especially from unknown sources. ↗
- →Monitor for unexpected FTP connections to affected WAGO PLC devices, as the hard-coded credentials can also be used for FTP access to exchange or delete the application. ↗
- →Alert on changes to network port states (open/closed) on affected WAGO devices, as exploitation can be used to open closed network ports. ↗
- ·No known public exploits specifically target this vulnerability at time of advisory publication. ↗
- ·Affected firmware versions are Series 750-88x prior to FW14 and Series 750-87x at various firmware versions (FW06–FW11 depending on model); patched devices running current firmware are not affected. ↗
- ·The hard-coded credentials are undocumented; the exact credential values are not publicly disclosed in available sources, limiting signature-based detection of the specific credential string. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6gg-5rm9-xp64: The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-
ghsa_unreviewed·2022-05-24
CVE-2019-10712 [CRITICAL] GHSA-r6gg-5rm9-xp64: The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
CISA ICS
WAGO Series 750-88x and 750-87x
cisa_ics·2019-04-16
WAGO Series 750-88x and 750-87x
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
WAGO Series 750-88x and 750-87x
Last RevisedApril 16, 2019
Alert CodeICSA-19-106-02
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: WAGO
- Equipment: Series 750-88x and 750-87x
- Vulnerability: Use of Hard-coded Credentials
## 2. RISK EVALUATION
This vulnerability allows a remote attacker to change the settings or alter the programming of the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Series 750-88x and 750-87x, programmable logic controllers, are affected:
- Series 750
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/108482https://cert.vde.com/de-de/advisories/vde-2019-008https://lists.apache.org/thread.html/r0066c1e862613de402fee04e81cbe00bcd64b64a2711beb9a13c3b25%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r25e25973e9577c62fd0221b4b52990851adf11cbe33036bd67d4b13d%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r37eb6579fa0bf94a72b6c978e2fee96f68a2b1b3ac1b1ce60aee86cf%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r386966780034aadee69ffd82d44555117c9339545b9ce990fe490a3e%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r80e8882c86c9c17a57396a5ef7c4f08878d629a0291243411be0de3a%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/ra37700b842790883b9082e6b281fb7596f571b13078a4856cd38f2c2%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rb47911c179c9f3e8ea3f134b5645e63cd20c6fc63bd0b43ab5864bd1%40%3Ccommits.cassandra.apache.org%3Ehttp://www.securityfocus.com/bid/108482https://cert.vde.com/de-de/advisories/vde-2019-008https://lists.apache.org/thread.html/r0066c1e862613de402fee04e81cbe00bcd64b64a2711beb9a13c3b25%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r25e25973e9577c62fd0221b4b52990851adf11cbe33036bd67d4b13d%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r37eb6579fa0bf94a72b6c978e2fee96f68a2b1b3ac1b1ce60aee86cf%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r386966780034aadee69ffd82d44555117c9339545b9ce990fe490a3e%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/r80e8882c86c9c17a57396a5ef7c4f08878d629a0291243411be0de3a%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/ra37700b842790883b9082e6b281fb7596f571b13078a4856cd38f2c2%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rb47911c179c9f3e8ea3f134b5645e63cd20c6fc63bd0b43ab5864bd1%40%3Ccommits.cassandra.apache.org%3E
2019-05-07
Published