This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

Project Subscriptions

Vendors Products
750-362 Subscribe
750-362 Firmware Subscribe
750-363 Subscribe
750-363 Firmware Subscribe
750-823 Subscribe
750-823 Firmware Subscribe
750-832 Subscribe
750-832\/000-002 Subscribe
750-832\/000-002 Firmware Subscribe
750-832 Firmware Subscribe
750-862 Subscribe
750-862 Firmware Subscribe
750-890\/025-000 Subscribe
750-890\/025-000 Firmware Subscribe
750-890\/025-001 Subscribe
750-890\/025-001 Firmware Subscribe
750-890\/025-002 Subscribe
750-890\/025-002 Firmware Subscribe
750-890\/040-000 Subscribe
750-890\/040-000 Firmware Subscribe
750-891 Subscribe
750-891 Firmware Subscribe
750-893 Subscribe
750-893 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21228 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Fixes

Solution

Update the device to the latest FW version.


Workaround

Restrict network access to the device. Do not directly connect the device to the internet. Disable unused TCP/UDP ports. Disable web-based management ports 80/443 after the configuration phase

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T18:33:25.112Z

Reserved: 2021-06-10T00:00:00

Link: CVE-2021-34578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-31T11:15:07.777

Modified: 2024-11-21T06:10:44.417

Link: CVE-2021-34578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses