Wago 762-3002 Firmware vulnerabilities
3 known vulnerabilities affecting wago/762-3002_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-12980HIGHCVSS 8.8PoCfixed in 022018-07-12
CVE-2018-12980 [HIGH] CWE-434 CVE-2018-12980: An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
nvd
CVE-2018-12979MEDIUMCVSS 6.5PoCfixed in 022018-07-12
CVE-2018-12979 [MEDIUM] CWE-732 CVE-2018-12979: An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.
nvd
CVE-2018-12981MEDIUMCVSS 5.4PoCfixed in 022018-07-12
CVE-2018-12981 [MEDIUM] CWE-79 CVE-2018-12981: An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browse
nvd