cbcvebase.
CVE-2021-34578
published 2021-08-31

CVE-2021-34578: This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

Affected

20 ranges
VendorProductVersion rangeFixed in
wago750-362_firmware<= fw07
wago750-363_firmware<= fw07
wago750-823_firmware<= fw07
wago750-832_000-002_firmware<= fw07
wago750-832_firmware<= fw07
wago750-862_firmware<= fw07
wago750-890_025-000_firmware<= fw07
wago750-890_025-001_firmware<= fw07
wago750-890_025-002_firmware<= fw07
wago750-890_040-000_firmware<= fw07
wago750-891_firmware<= fw07
wago750-893_firmware<= fw07
wagoplc750-362 – FW07
wagoplc750-363 – FW07
wagoplc750-823 – FW07
wagoplc750-832/xxx-xxx – FW07
wagoplc750-862 – FW07
wagoplc750-890/xxx-xxx – FW07
wagoplc750-891 – FW07
wagoplc750-893 – FW07