CVE-2018-8836

Severity CVSS v4.0:
Pending analysis
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
03/04/2018
Last modified:
09/10/2019

Description

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:750-880_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-880:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-881_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-881:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-852_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-852:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-882_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-882:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-885_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-885:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-831_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-831:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-889_firmware:*:*:*:*:*:*:*:* 10 (including)
cpe:2.3:h:wago:750-889:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-829_firmware:*:*:*:*:*:*:*:* 10 (including)