VYPR

750 363 Firmware

by Wago

CVEs (4)

  • CVE-2021-34578CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

  • CVE-2020-12506CriSep 30, 2020
    risk 0.59cvss 9.1epss 0.01

    Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO…

  • CVE-2023-1150HigJun 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.

  • CVE-2018-16210MedOct 12, 2018
    risk 0.40cvss 6.1epss 0.01

    WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.