Description
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
No analysis available yet.
Remediation
Vendor Solution
Update the device to the latest FW version.
Vendor Workaround
Restrict network access to the device. Do not directly connect the device to the internet. Disable unused TCP/UDP ports. Disable web-based management ports 80/443 after the configuration phase
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21228 | This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2020-044 |
|
History
No history.
Subscriptions
Wago
Subscribe
750-362
Subscribe
750-362 Firmware
Subscribe
750-363
Subscribe
750-363 Firmware
Subscribe
750-823
Subscribe
750-823 Firmware
Subscribe
750-832
Subscribe
750-832\/000-002
Subscribe
750-832\/000-002 Firmware
Subscribe
750-832 Firmware
Subscribe
750-862
Subscribe
750-862 Firmware
Subscribe
750-890\/025-000
Subscribe
750-890\/025-000 Firmware
Subscribe
750-890\/025-001
Subscribe
750-890\/025-001 Firmware
Subscribe
750-890\/025-002
Subscribe
750-890\/025-002 Firmware
Subscribe
750-890\/040-000
Subscribe
750-890\/040-000 Firmware
Subscribe
750-891
Subscribe
750-891 Firmware
Subscribe
750-893
Subscribe
750-893 Firmware
Subscribe
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-16T18:33:25.112Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34578
No data.
Status : Modified
Published: 2021-08-31T11:15:07.777
Modified: 2024-11-21T06:10:44.417
Link: CVE-2021-34578
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD