VYPR

750 8202 Firmware

by Wago

CVEs (25)

  • CVE-2022-22511MedMar 9, 2022
    risk 0.35cvss 5.4epss 0.01

    Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.

  • CVE-2021-21000MedMay 24, 2021
    risk 0.35cvss 5.3epss 0.01

    On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

  • CVE-2021-30187MedMay 25, 2021
    risk 0.34cvss 5.3epss 0.00

    CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

  • CVE-2023-1620MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

  • CVE-2023-1619MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

Page 2 of 2