Show filters
105 Total Results
Displaying 11-20 of 105
Sort by:
Attacker Value
Unknown

CVE-2015-10123

Disclosure Date: March 13, 2024 (last updated January 05, 2025)
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.
0
Attacker Value
Unknown

CVE-2023-5188

Disclosure Date: December 05, 2023 (last updated December 12, 2023)
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.
Attacker Value
Unknown

CVE-2023-4149

Disclosure Date: November 21, 2023 (last updated January 04, 2025)
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based management.
Attacker Value
Unknown

CVE-2023-3379

Disclosure Date: November 20, 2023 (last updated October 02, 2024)
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
Attacker Value
Unknown

CVE-2023-4089

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Attacker Value
Unknown

CVE-2023-1620

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
Attacker Value
Unknown

CVE-2023-1619

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
Attacker Value
Unknown

CVE-2023-1150

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
Attacker Value
Unknown

CVE-2023-1698

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Attacker Value
Unknown

CVE-2022-45140

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.