CVE-2021-34578

Severity
8.1HIGH
EPSS
0.3%
top 43.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 24

Description

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages13 packages

🔴Vulnerability Details

2
GHSA
GHSA-m68m-r5xj-h4vj: This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructe2022-05-24
CVEList
WAGO: Authentication Vulnerability in Web-Based Management2021-08-31