CRITICAL · 9.8

CVE-2021-34578

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO...

Vulnerability Description

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Wago750-890\/040-000 Firmware<= fw07
Wago750-890\/040-000-
Wago750-890\/025-001 Firmware<= fw07
Wago750-890\/025-001-
Wago750-890\/025-002 Firmware<= fw07
Wago750-890\/025-002-
Wago750-890\/025-000 Firmware<= fw07
Wago750-890\/025-000-
Wago750-832\/000-002 Firmware<= fw07
Wago750-832\/000-002-
Wago750-362 Firmware<= fw07
Wago750-362-
Wago750-823 Firmware<= fw07
Wago750-823-
Wago750-832 Firmware<= fw07
Wago750-832-
Wago750-363 Firmware<= fw07
Wago750-363-
Wago750-862 Firmware<= fw07
Wago750-862-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-34578?

CVE-2021-34578 is a vulnerability with a CVSS score of 9.8 (CRITICAL). This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO...

How severe is CVE-2021-34578?

CVE-2021-34578 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-34578?

Check the references section above for vendor advisories and patch information. Affected products include: Wago 750-890\/040-000 Firmware, Wago 750-890\/040-000, Wago 750-890\/025-001 Firmware, Wago 750-890\/025-001, Wago 750-890\/025-002 Firmware.