Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-1620

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
Attacker Value
Unknown

CVE-2023-1619

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
Attacker Value
Unknown

CVE-2020-12069

Disclosure Date: December 26, 2022 (last updated October 04, 2024)
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Attacker Value
Unknown

CVE-2021-21000

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
Attacker Value
Unknown

CVE-2021-21001

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.