Wago 750-8202 Firmware vulnerabilities

27 known vulnerabilities affecting wago/750-8202_firmware.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH12MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2023-1619MEDIUMCVSS 4.9fixed in fw22vfw222023-06-26
CVE-2023-1619 [MEDIUM] CWE-1288 CVE-2023-1619: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
nvd
CVE-2023-1620MEDIUMCVSS 4.9fixed in fw22vfw222023-06-26
CVE-2023-1620 [MEDIUM] CWE-1288 CVE-2023-1620: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
nvd
CVE-2020-12069HIGHCVSS 7.8fixed in 03.06.19\(18\)2022-12-26
CVE-2020-12069 [HIGH] CWE-916 CVE-2020-12069: In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Contro In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
nvd
CVE-2021-34569CRITICALCVSS 9.8fixed in 18v182022-11-09
CVE-2021-34569 [CRITICAL] CWE-787 CVE-2021-34569: In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet conta In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.
nvd
CVE-2021-34566CRITICALCVSS 9.1fixed in 18v182022-11-09
CVE-2021-34566 [CRITICAL] CWE-120 CVE-2021-34566: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
nvd
CVE-2021-34567HIGHCVSS 8.2fixed in 18v182022-11-09
CVE-2021-34567 [HIGH] CWE-125 CVE-2021-34567: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.
nvd
CVE-2021-34568HIGHCVSS 7.5fixed in 18v182022-11-09
CVE-2021-34568 [HIGH] CWE-770 CVE-2021-34568: In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.
nvd
CVE-2022-22511MEDIUMCVSS 5.4≥ fw16, < fw222022-03-09
CVE-2022-22511 [MEDIUM] CWE-79 CVE-2022-22511: Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) att Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
nvd
CVE-2021-34584CRITICALCVSS 9.1fixed in fw202021-10-26
CVE-2021-34584 [CRITICAL] CWE-126 CVE-2021-34584: Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a de Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
nvd
CVE-2021-34585HIGHCVSS 7.5fixed in fw202021-10-26
CVE-2021-34585 [HIGH] CWE-252 CVE-2021-34585: In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser err In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
nvd
CVE-2021-34595HIGHCVSS 8.1fixed in fw202021-10-26
CVE-2021-34595 [HIGH] CWE-823 CVE-2021-34595: A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
nvd
CVE-2021-34593HIGHCVSS 7.5fixed in fw202021-10-26
CVE-2021-34593 [HIGH] CWE-755 CVE-2021-34593: In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated c In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
nvd
CVE-2021-34586HIGHCVSS 7.5fixed in fw202021-10-26
CVE-2021-34586 [HIGH] CWE-476 CVE-2021-34586: In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.
nvd
CVE-2021-34583HIGHCVSS 7.5fixed in fw202021-10-26
CVE-2021-34583 [HIGH] CWE-122 CVE-2021-34583: Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a den Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
nvd
CVE-2021-34596MEDIUMCVSS 6.5fixed in fw202021-10-26
CVE-2021-34596 [MEDIUM] CWE-824 CVE-2021-34596: A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
nvd
CVE-2021-30189CRITICALCVSS 9.8fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30189 [CRITICAL] CWE-787 CVE-2021-30189: CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
nvd
CVE-2021-30190CRITICALCVSS 9.8fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30190 [CRITICAL] CWE-306 CVE-2021-30190: CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
nvd
CVE-2021-30192CRITICALCVSS 9.8fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30192 [CRITICAL] CVE-2021-30192: CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
nvd
CVE-2021-30194CRITICALCVSS 9.1fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30194 [CRITICAL] CWE-125 CVE-2021-30194: CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
nvd
CVE-2021-30188CRITICALCVSS 9.8fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30188 [CRITICAL] CWE-787 CVE-2021-30188: CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
nvd