Vulnerabilities > Wago > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-13 CVE-2021-20997 Insufficiently Protected Credentials vulnerability in Wago products
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.
network
low complexity
wago CWE-522
7.5
2021-01-22 CVE-2020-12525 Deserialization of Untrusted Data vulnerability in multiple products
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
7.8
2020-12-10 CVE-2020-12516 Unspecified vulnerability in Wago products
Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.
network
low complexity
wago
7.5
2020-09-30 CVE-2020-12505 Missing Authentication for Critical Function vulnerability in Wago products
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication.
network
low complexity
wago CWE-306
8.2
2020-06-11 CVE-2020-6090 Insufficient Verification of Data Authenticity vulnerability in Wago Pfc200 Firmware 03.03.10(15)
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15).
network
low complexity
wago CWE-345
7.2
2020-03-23 CVE-2019-5186 Classic Buffer Overflow vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200.
local
high complexity
wago CWE-120
7.0
2020-03-23 CVE-2019-5185 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200.
local
high complexity
wago CWE-787
7.0
2020-03-23 CVE-2019-5184 Double Free vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200.
local
low complexity
wago CWE-415
7.8
2020-03-12 CVE-2019-5181 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14).
local
low complexity
wago CWE-787
7.8
2020-03-12 CVE-2019-5180 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14).
local
low complexity
wago CWE-787
7.8