VYPR

750 831 Firmware

by Wago

CVEs (26)

  • CVE-2018-16210MedOct 12, 2018
    risk 0.40cvss 6.1epss 0.01

    WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.

  • CVE-2021-21000MedMay 24, 2021
    risk 0.35cvss 5.3epss 0.01

    On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

  • CVE-2018-8836MedApr 3, 2018
    risk 0.35cvss 5.3epss 0.04

    Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be…

  • CVE-2021-30187MedMay 25, 2021
    risk 0.34cvss 5.3epss 0.00

    CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

  • CVE-2023-1620MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

  • CVE-2023-1619MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

Page 2 of 2