Vendor CVEs
Wago
All CVEs
121 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-5106 | Med | 0.36 | 5.5 | 0.00 | Mar 11, 2020 | A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain… | ||
| CVE-2022-22511 | Med | 0.35 | 5.4 | 0.01 | Mar 9, 2022 | Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised. | ||
| CVE-2021-21000 | Med | 0.35 | 5.3 | 0.01 | May 24, 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. | ||
| CVE-2021-20996 | Med | 0.35 | 5.3 | 0.01 | May 13, 2021 | In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. | ||
| CVE-2021-20993 | Med | 0.35 | 5.3 | 0.01 | May 13, 2021 | In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. | ||
| CVE-2019-5135 | Med | 0.35 | 5.3 | 0.01 | Mar 11, 2020 | An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user… | ||
| CVE-2019-5073 | Med | 0.35 | 5.3 | 0.02 | Dec 18, 2019 | An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool… | ||
| CVE-2019-18202 | Med | 0.35 | 5.3 | 0.02 | Oct 19, 2019 | Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests. | ||
| CVE-2018-8836 | Med | 0.35 | 5.3 | 0.04 | Apr 3, 2018 | Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be… | ||
| CVE-2023-3379 | Med | 0.34 | 5.3 | 0.00 | Nov 20, 2023 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | ||
| CVE-2022-45139 | Med | 0.34 | 5.3 | 0.00 | Feb 27, 2023 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a… | ||
| CVE-2021-30187 | Med | 0.34 | 5.3 | 0.00 | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. | ||
| CVE-2021-20995 | Med | 0.34 | 5.3 | 0.01 | May 13, 2021 | In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. | ||
| CVE-2023-1620 | Med | 0.32 | 4.9 | 0.01 | Jun 26, 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime. | ||
| CVE-2023-1619 | Med | 0.32 | 4.9 | 0.01 | Jun 26, 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet. | ||
| CVE-2023-5872 | Med | 0.28 | 4.3 | 0.00 | Apr 16, 2026 | In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint. | ||
| CVE-2023-4089 | Low | 0.18 | 2.7 | 0.00 | Oct 17, 2023 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected. | ||
| CVE-2020-8597 | Cri | 0.02 | 9.8 | 0.20 | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | ||
| CVE-2026-4769 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this… | ||
| CVE-2012-4879 | 0.00 | — | 0.03 | Sep 7, 2012 | The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest… | |||
| CVE-2012-3013 | 0.00 | — | 0.03 | Sep 7, 2012 | WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session. |
- risk 0.36cvss 5.5epss 0.00
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain…
- risk 0.35cvss 5.4epss 0.01
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
- risk 0.35cvss 5.3epss 0.01
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
- risk 0.35cvss 5.3epss 0.01
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
- risk 0.35cvss 5.3epss 0.01
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
- risk 0.35cvss 5.3epss 0.01
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user…
- risk 0.35cvss 5.3epss 0.02
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool…
- risk 0.35cvss 5.3epss 0.02
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
- risk 0.35cvss 5.3epss 0.04
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be…
- risk 0.34cvss 5.3epss 0.00
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
- risk 0.34cvss 5.3epss 0.00
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a…
- risk 0.34cvss 5.3epss 0.00
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
- risk 0.34cvss 5.3epss 0.01
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.
- risk 0.32cvss 4.9epss 0.01
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
- risk 0.32cvss 4.9epss 0.01
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
- risk 0.28cvss 4.3epss 0.00
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
- risk 0.18cvss 2.7epss 0.00
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
- risk 0.02cvss 9.8epss 0.20
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
- risk 0.00cvss 9.8epss 0.00
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this…
- CVE-2012-4879Sep 7, 2012risk 0.00cvss —epss 0.03
The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest…
- CVE-2012-3013Sep 7, 2012risk 0.00cvss —epss 0.03
WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session.
Page 3 of 3