cbcvebase.
CVE-2021-20998
published 2021-05-13

CVE-2021-20998: In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.3th percentile
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

Affected

10 ranges
VendorProductVersion rangeFixed in
wago0852-0303unspecified – V1.2.3.S0
wago0852-0303_firmware<= 1.2.3.s0
wago0852-1305unspecified – V1.1.7.S0
wago0852-1305_000-001unspecified – V1.0.4.S0
wago0852-1305_000-001_firmware<= 1.0.4.s0
wago0852-1305_firmware<= 1.1.7.s0
wago0852-1505unspecified – V1.1.6.S0
wago0852-1505_000-001unspecified – V1.0.4.S0
wago0852-1505_000-001_firmware<= 1.0.4.s0
wago0852-1505_firmware<= 1.1.6.s0

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.