Wago 750-362 Firmware vulnerabilities
4 known vulnerabilities affecting wago/750-362_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-1150HIGHCVSS 7.5fixed in fw112023-06-26
CVE-2023-1150 [HIGH] CWE-772 CVE-2023-1150: Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated re
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
nvd
CVE-2021-34578HIGHCVSS 8.1≤ fw072021-08-31
CVE-2021-34578 [CRITICAL] CWE-287 CVE-2021-34578: This vulnerability allows an attacker who has access to the WBM to read and write settings-parameter
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
nvd
CVE-2020-12506CRITICALCVSS 9.1≤ fw032020-09-30
CVE-2020-12506 [CRITICAL] CWE-306 CVE-2020-12506: Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attac
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in ver
nvd
CVE-2018-16210MEDIUMCVSS 6.1fixed in 052018-10-12
CVE-2018-16210 [MEDIUM] CWE-79 CVE-2018-16210: WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XS
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
nvd