This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21228 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Fixes

Solution

Update the device to the latest FW version.


Workaround

Restrict network access to the device. Do not directly connect the device to the internet. Disable unused TCP/UDP ports. Disable web-based management ports 80/443 after the configuration phase

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T18:33:25.112Z

Reserved: 2021-06-10T00:00:00

Link: CVE-2021-34578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-31T11:15:07.777

Modified: 2024-11-21T06:10:44.417

Link: CVE-2021-34578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.