Wago 750-8202 Firmware vulnerabilities
27 known vulnerabilities affecting wago/750-8202_firmware.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH12MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2021-30191P3HIGHCVSS 7.5fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30191 [HIGH] CWE-120 CVE-2021-30191: CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
nvd
CVE-2021-34585P3HIGHCVSS 7.5fixed in fw202021-10-26
CVE-2021-34585 [HIGH] CWE-252 CVE-2021-34585: In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser err
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
nvd
CVE-2021-34596P4MEDIUMCVSS 6.5fixed in fw202021-10-26
CVE-2021-34596 [MEDIUM] CWE-824 CVE-2021-34596: A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
nvd
CVE-2021-30187P4MEDIUMCVSS 5.3fixed in 03.06.19_\(18\)2021-05-25
CVE-2021-30187 [MEDIUM] CWE-78 CVE-2021-30187: CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
nvd
CVE-2022-22511P4MEDIUMCVSS 5.4≥ fw16, < fw222022-03-09
CVE-2022-22511 [MEDIUM] CWE-79 CVE-2022-22511: Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) att
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
nvd
CVE-2023-1620P4MEDIUMCVSS 4.9fixed in fw22vfw222023-06-26
CVE-2023-1620 [MEDIUM] CWE-1288 CVE-2023-1620: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
nvd
CVE-2023-1619P4MEDIUMCVSS 4.9fixed in fw22vfw222023-06-26
CVE-2023-1619 [MEDIUM] CWE-1288 CVE-2023-1619: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
nvd
← Previous2 / 2