CVE-2024-41967

Severity
8.1HIGH
EPSS
1.3%
top 20.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages15 packages

CVEListV5wago/cc100_0751-9x010.0.04.5.10 (FW27)
CVEListV5wago/cc100_0751/9x010.0.004.03.03 (72)+1
CVEListV5wago/tp600_0762-420x/8000-000x0.0.04.5.10 (FW27)
CVEListV5wago/tp600_0762-430x/8000-000x0.0.04.5.10 (FW27)
CVEListV5wago/tp600_0762-520x/8000-000x0.0.04.5.10 (FW27)

🔴Vulnerability Details

2
CVEList
WAGO: Boot Mode Manipulation in Multiple Devices2024-11-18
GHSA
GHSA-j34c-54rj-94x3: A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process o2024-11-18