CVE-2021-34566
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
09/11/2022
Last modified:
07/11/2023
Description
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wago:750-8100_firmware:*:*:*:*:*:*:*:* | 18 (excluding) | |
| cpe:2.3:o:wago:750-8100_firmware:18:-:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8100_firmware:18:patch_1:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8100_firmware:18:patch_2:*:*:*:*:*:* | ||
| cpe:2.3:h:wago:750-8100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101_firmware:*:*:*:*:*:*:*:* | 18 (excluding) | |
| cpe:2.3:o:wago:750-8101_firmware:18:-:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101_firmware:18:patch_1:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101_firmware:18:patch_2:*:*:*:*:*:* | ||
| cpe:2.3:h:wago:750-8101:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101\/025-000_firmware:*:*:*:*:*:*:*:* | 18 (excluding) | |
| cpe:2.3:o:wago:750-8101\/025-000_firmware:18:-:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101\/025-000_firmware:18:patch_1:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101\/025-000_firmware:18:patch_2:*:*:*:*:*:* | ||
| cpe:2.3:h:wago:750-8101\/025-000:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



