Description
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Published: 2021-05-24
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

WAGO recommends all effected users with CODESYS 2.3 Runtime PLCs to update to the firmware versions listed at https://cert.vde.com/en-us/advisories/vde-2021-014 in the solution paragraph.


Vendor Workaround

Use general security best practices to protect systems from local and network attacks. Do not allow direct access to the device from untrusted networks. Update to the latest firmware according to the table in chapter solutions.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8410 On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
History

No history.

Subscriptions

Wago 750-8202 750-8202 Firmware 750-8203 750-8203 Firmware 750-8204 750-8204 Firmware 750-8206 750-8206 Firmware 750-8207 750-8207 Firmware 750-8208 750-8208 Firmware 750-8210 750-8210 Firmware 750-8211 750-8211 Firmware 750-8212 750-8212 Firmware 750-8213 750-8213 Firmware 750-8214 750-8214 Firmware 750-8216 750-8216 Firmware 750-8217 750-8217 Firmware 750-823 750-823 Firmware 750-829 750-829 Firmware 750-831 750-831 Firmware 750-832 750-832 Firmware 750-852 750-852 Firmware 750-862 750-862 Firmware 750-880 750-880 Firmware 750-881 750-881 Firmware 750-882 750-882 Firmware 750-885 750-885 Firmware 750-889 750-889 Firmware 750-890 750-890 Firmware 750-891 750-891 Firmware 750-893 750-893 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T16:19:02.930Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-21001

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-05-24T11:15:07.980

Modified: 2025-08-15T20:21:10.680

Link: CVE-2021-21001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses