CVE-2021-34578

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
31/08/2021
Last modified:
08/09/2021

Description

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:750-890\/040-000_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-890\/040-000:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-890\/025-001_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-890\/025-001:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-890\/025-002_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-890\/025-002:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-890\/025-000_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-890\/025-000:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-832\/000-002_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-832\/000-002:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-362_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-362:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-823_firmware:*:*:*:*:*:*:*:* fw07 (including)
cpe:2.3:h:wago:750-823:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-832_firmware:*:*:*:*:*:*:*:* fw07 (including)


References to Advisories, Solutions, and Tools