AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Wago
WA
Platform

Wago

750 Series modular fieldbus I/O, PFC200 controllers, WAGO-I/O-PRO and e!COCKPIT engineering software.

https://www.wago.com →
83
Total CVEs
0
Resources
26
CRIT
39
HIGH
17
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
17 / 83
CVE-2018-12979MEDIUM

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.

Jul 12, 2018
6.5
CVE-2018-16210MEDIUM

WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.

Oct 12, 2018
6.1
CVE-2013-0253MEDIUM

The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.

Apr 9, 2013
5.8
CVE-2019-5177MEDIUM

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). The destination buffer sp+0x440 is overflowed with the call to sprintf() for any domainname values that are greater than 1024-len(‘/etc/config-tools/edit_dns_server domain-name=‘) in length. A domainname value of length 0x3fa will cause the service to crash.

Mar 12, 2020
5.5
CVE-2019-5176MEDIUM

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.The destination buffer sp+0x40 is overflowed with the call to sprintf() for any gateway values that are greater than 512-len(‘/etc/config-tools/config_default_gateway number=0 state=enabled value=‘) in length. A gateway value of length 0x7e2 will cause the service to crash.

Mar 12, 2020
5.5
CVE-2019-5182MEDIUM

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.The destination buffer sp+0x440 is overflowed with the call to sprintf() for any type values that are greater than 1024-len(‘/etc/config-tools/config_interfaces interface=X1 state=enabled config-type=‘) in length. A type value of length 0x3d9 will cause the service to crash.

Mar 11, 2020
5.5
CVE-2018-12981MEDIUM

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.

Jul 12, 2018
5.4
CVE-2023-3379MEDIUM

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Nov 20, 2023
5.3
CVE-2021-21000MEDIUM

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

May 24, 2021
5.3
CVE-2021-20996MEDIUM

In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

May 13, 2021
5.3
CVE-2021-20995MEDIUM

In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

May 13, 2021
5.3
CVE-2021-20993MEDIUM

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.

May 13, 2021
5.3
CVE-2019-5135MEDIUM

An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12).

Mar 11, 2020
5.3
CVE-2019-5073MEDIUM

An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
5.3
CVE-2019-18202MEDIUM

Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.

Oct 19, 2019
5.3
CVE-2009-4007MEDIUM

Unspecified vulnerability in the NormaliseTrainConsist function in src/train_cmd.cpp in OpenTTD before 0.7.5-RC1 allows remote attackers to cause a denial of service (daemon crash) via certain game actions involving a wagon and a dual-headed engine.

Dec 28, 2009
5.0
CVE-2023-1619MEDIUM

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

Jun 26, 2023
4.9
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2018-12979MEDIUM
6.5
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW …Jul 12, 2018›
CVE-2018-16210MEDIUM
6.1
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XS…Oct 12, 2018›
CVE-2013-0253MEDIUM
5.8
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificat…Apr 9, 2013›
CVE-2019-5177MEDIUM
5.5
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5176MEDIUM
5.5
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5182MEDIUM
5.5
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 11, 2020›
CVE-2018-12981MEDIUM
5.4
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW …Jul 12, 2018›
CVE-2023-3379MEDIUM
5.3
Wago web-based management of multiple products has a vulnerability which allows an local authenticat…Nov 20, 2023›
CVE-2021-21000MEDIUM
5.3
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with …May 24, 2021›
CVE-2021-20996MEDIUM
5.3
In multiple managed switches by WAGO in different versions special crafted requests can lead to cook…May 13, 2021›
CVE-2021-20995MEDIUM
5.3
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI…May 13, 2021›
CVE-2021-20993MEDIUM
5.3
In multiple managed switches by WAGO in different versions the activated directory listing provides …May 13, 2021›
CVE-2019-5135MEDIUM
5.3
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the We…Mar 11, 2020›
CVE-2019-5073MEDIUM
5.3
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functio…Dec 18, 2019›
CVE-2019-18202MEDIUM
5.3
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to impro…Oct 19, 2019›
CVE-2009-4007MEDIUM
5.0
Unspecified vulnerability in the NormaliseTrainConsist function in src/train_cmd.cpp in OpenTTD befo…Dec 28, 2009›
CVE-2023-1619MEDIUM
4.9
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high priv…Jun 26, 2023›