Vulnerabilities > Wago

DATE CVE VULNERABILITY TITLE RISK
2019-06-17 CVE-2019-12550 Use of Hard-coded Credentials vulnerability in Wago products
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
network
low complexity
wago CWE-798
critical
10.0
2019-06-17 CVE-2019-12549 Use of Hard-coded Credentials vulnerability in Wago products
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon.
network
low complexity
wago CWE-798
critical
10.0
2019-05-07 CVE-2019-10712 Use of Hard-coded Credentials vulnerability in Wago products
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
network
low complexity
wago CWE-798
critical
9.8
2019-04-17 CVE-2019-10953 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions.
5.0
2018-10-12 CVE-2018-16210 Cross-site Scripting vulnerability in Wago 750-881 Ethernet Controller Devices Firmware 01.08.01(10)/01.09.18(13)
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
network
wago CWE-79
4.3
2018-07-12 CVE-2018-12981 Cross-site Scripting vulnerability in Wago products
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02.
network
wago CWE-79
3.5
2018-07-12 CVE-2018-12980 Unrestricted Upload of File with Dangerous Type vulnerability in Wago products
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02.
network
low complexity
wago CWE-434
6.5
2018-07-12 CVE-2018-12979 Incorrect Permission Assignment for Critical Resource vulnerability in Wago products
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02.
network
low complexity
wago CWE-732
5.5
2018-04-03 CVE-2018-8836 Improper Resource Shutdown or Release vulnerability in Wago products
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools.
network
low complexity
wago CWE-404
5.0
2018-02-13 CVE-2018-5459 Improper Authentication vulnerability in Wago Pfc200 Firmware
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X.
network
low complexity
wago CWE-287
7.5