Wago 750-8101 Firmware vulnerabilities
7 known vulnerabilities affecting wago/750-8101_firmware.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-12069HIGHCVSS 7.8fixed in 03.06.19\(18\)2022-12-26
CVE-2020-12069 [HIGH] CWE-916 CVE-2020-12069: In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Contro
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
nvd
CVE-2021-34569CRITICALCVSS 9.8fixed in 18v182022-11-09
CVE-2021-34569 [CRITICAL] CWE-787 CVE-2021-34569: In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet conta
In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.
nvd
CVE-2021-34566CRITICALCVSS 9.1fixed in 18v182022-11-09
CVE-2021-34566 [CRITICAL] CWE-120 CVE-2021-34566: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
nvd
CVE-2021-34567HIGHCVSS 8.2fixed in 18v182022-11-09
CVE-2021-34567 [HIGH] CWE-125 CVE-2021-34567: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.
nvd
CVE-2021-34568HIGHCVSS 7.5fixed in 18v182022-11-09
CVE-2021-34568 [HIGH] CWE-770 CVE-2021-34568: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.
nvd
CVE-2022-3281HIGHCVSS 7.5≥ 03.01.07\(13\), ≤ 03.10.08\(22\)2022-10-17
CVE-2022-3281 [HIGH] CWE-440 CVE-2022-3281: WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in m
WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumvent the reach the network that should be protected by the MAC address filter.
nvd
CVE-2022-22511MEDIUMCVSS 5.4≥ fw16, < fw222022-03-09
CVE-2022-22511 [MEDIUM] CWE-79 CVE-2022-22511: Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) att
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
nvd