Description
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Published: 2021-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update the device to the latest FW version.


Vendor Workaround

Restrict network access to the device. Do not directly connect the device to the internet. Disable unused TCP/UDP ports. Disable web-based management ports 80/443 after the configuration phase

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21228 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
History

No history.

Subscriptions

Wago 750-362 750-362 Firmware 750-363 750-363 Firmware 750-823 750-823 Firmware 750-832 750-832\/000-002 750-832\/000-002 Firmware 750-832 Firmware 750-862 750-862 Firmware 750-890\/025-000 750-890\/025-000 Firmware 750-890\/025-001 750-890\/025-001 Firmware 750-890\/025-002 750-890\/025-002 Firmware 750-890\/040-000 750-890\/040-000 Firmware 750-891 750-891 Firmware 750-893 750-893 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T18:33:25.112Z

Reserved: 2021-06-10T00:00:00.000Z

Link: CVE-2021-34578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-31T11:15:07.777

Modified: 2024-11-21T06:10:44.417

Link: CVE-2021-34578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses