Wago 750-881 Firmware vulnerabilities
27 known vulnerabilities affecting wago/750-881_firmware.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH10MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2021-34585P3HIGHCVSS 7.5fixed in fw172021-10-26
CVE-2021-34585 [HIGH] CWE-252 CVE-2021-34585: In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser err
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
nvd
CVE-2018-8836P4MEDIUMCVSS 5.3≤ 102018-04-03
CVE-2018-8836 [MEDIUM] CWE-404 CVE-2018-8836: Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage o
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may re
nvd
CVE-2021-34596P4MEDIUMCVSS 6.5fixed in fw172021-10-26
CVE-2021-34596 [MEDIUM] CWE-824 CVE-2021-34596: A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
nvd
CVE-2021-30187P4MEDIUMCVSS 5.3fixed in fw152021-05-25
CVE-2021-30187 [MEDIUM] CWE-78 CVE-2021-30187: CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
nvd
CVE-2023-1620P4MEDIUMCVSS 4.9fixed in fw172023-06-26
CVE-2023-1620 [MEDIUM] CWE-1288 CVE-2023-1620: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
nvd
CVE-2023-1619P4MEDIUMCVSS 4.9fixed in fw172023-06-26
CVE-2023-1619 [MEDIUM] CWE-1288 CVE-2023-1619: Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
nvd
CVE-2018-16210P4MEDIUMCVSS 6.1fixed in 142018-10-12
CVE-2018-16210 [MEDIUM] CWE-79 CVE-2018-16210: WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XS
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
nvd
← Previous2 / 2