cbcvebase.
CVE-2021-34578
published 2021-08-31

CVE-2021-34578: This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed…

PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.96%
58.0th percentile
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

Affected

20 ranges
VendorProductVersion rangeFixed in
wago750-362_firmware<= fw07
wago750-363_firmware<= fw07
wago750-823_firmware<= fw07
wago750-832_000-002_firmware<= fw07
wago750-832_firmware<= fw07
wago750-862_firmware<= fw07
wago750-890_025-000_firmware<= fw07
wago750-890_025-001_firmware<= fw07
wago750-890_025-002_firmware<= fw07
wago750-890_040-000_firmware<= fw07
wago750-891_firmware<= fw07
wago750-893_firmware<= fw07
wagoplc750-362 – FW07
wagoplc750-363 – FW07
wagoplc750-823 – FW07
wagoplc750-832/xxx-xxx – FW07
wagoplc750-862 – FW07
wagoplc750-890/xxx-xxx – FW07
wagoplc750-891 – FW07
wagoplc750-893 – FW07

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.