On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Fixes

Solution

WAGO recommends all effected users with CODESYS 2.3 Runtime PLCs to update to the firmware versions listed at https://cert.vde.com/en-us/advisories/vde-2021-014 in the solution paragraph.


Workaround

Use general security best practices to protect systems from local and network attacks. Do not allow direct access to the device from untrusted networks. Update to the latest firmware according to the table in chapter solutions.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T16:19:02.930Z

Reserved: 2020-12-17T00:00:00

Link: CVE-2021-21001

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-05-24T11:15:07.980

Modified: 2025-08-15T20:21:10.680

Link: CVE-2021-21001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.