On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
📦
750-890
Vendor: wago
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
3
Remote Access
Total CVEs
23
Total Indexed
Avg. EPSS
2.41%
Exploit Prob.
Security Vulnerability Index
Page 3 / 3
5.3
CVSS
Severity: MEDIUM
9.1
CVSS
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.
Severity: CRITICAL
6.1
CVSS
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
Severity: MEDIUM