VYPR

750 8202 Firmware

by Wago

CVEs (27)

  • CVE-2021-30186HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.07

    CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

  • CVE-2021-34596MedOct 26, 2021
    risk 0.42cvss 6.5epss 0.01

    A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

  • CVE-2022-22511MedMar 9, 2022
    risk 0.35cvss 5.4epss 0.01

    Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.

  • CVE-2021-21000MedMay 24, 2021
    risk 0.35cvss 5.3epss 0.01

    On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

  • CVE-2021-30187MedMay 25, 2021
    risk 0.34cvss 5.3epss 0.00

    CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

  • CVE-2023-1620MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

  • CVE-2023-1619MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

Page 2 of 2