Show filters
105 Total Results
Displaying 91-100 of 105
Sort by:
Attacker Value
Unknown

CVE-2019-12550

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
0
Attacker Value
Unknown

CVE-2019-12549

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.
0
Attacker Value
Unknown

CVE-2019-10712

Disclosure Date: May 07, 2019 (last updated November 08, 2023)
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
0
Attacker Value
Unknown

CVE-2019-10953

Disclosure Date: April 17, 2019 (last updated November 27, 2024)
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
Attacker Value
Unknown

CVE-2018-16210

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
0
Attacker Value
Unknown

CVE-2018-12981

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.
Attacker Value
Unknown

CVE-2018-12980

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
Attacker Value
Unknown

CVE-2018-12979

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.
Attacker Value
Unknown

CVE-2018-8836

Disclosure Date: April 03, 2018 (last updated November 26, 2024)
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
0
Attacker Value
Unknown

CVE-2018-5459

Disclosure Date: February 13, 2018 (last updated November 26, 2024)
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
0