cbcvebase.
CVE-2021-21001
published 2021-05-24

CVE-2021-21001: On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file…

PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.13%
62.9th percentile
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
wago750-8202_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8203_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8204_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8206_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8207_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8208_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8210_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8211_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8212_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8213_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8214_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8216_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-8217_firmware< 03.06.19_\(18\)03.06.19_\(18\)
wago750-823_firmware< fw08fw08
wago750-829_firmware< fw15fw15
wago750-831_firmware< fw15fw15
wago750-832_firmware< fw08fw08
wago750-852_firmware< fw15fw15
wago750-862_firmware< fw08fw08
wago750-880_firmware< fw16fw16
wago750-881_firmware< fw15fw15
wago750-882_firmware< fw15fw15
wago750-885_firmware< fw15fw15
wago750-889_firmware< fw15fw15
wago750-890_firmware< fw08fw08

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.