Vulnerabilities > Wago > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-20 CVE-2023-3379 Incorrect Authorization vulnerability in Wago products
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
local
low complexity
wago CWE-863
5.3
2023-06-26 CVE-2023-1619 Unspecified vulnerability in Wago products
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
network
low complexity
wago
4.9
2023-06-26 CVE-2023-1620 Improper Validation of Consistency within Input vulnerability in Wago products
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
network
low complexity
wago CWE-1288
4.9
2023-02-27 CVE-2022-45137 Cross-site Scripting vulnerability in Wago products
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser.
network
low complexity
wago CWE-79
6.1
2023-02-27 CVE-2022-45139 Origin Validation Error vulnerability in Wago products
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver.
network
low complexity
wago CWE-346
5.3
2023-01-19 CVE-2022-3738 Missing Authentication for Critical Function vulnerability in Wago products
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists.
network
high complexity
wago CWE-306
5.9
2022-03-09 CVE-2022-22511 Cross-site Scripting vulnerability in Wago products
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks.
network
low complexity
wago CWE-79
5.4
2021-05-24 CVE-2021-21001 Path Traversal vulnerability in Wago products
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
network
low complexity
wago CWE-22
6.5
2021-05-13 CVE-2021-20993 Information Exposure vulnerability in Wago products
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
network
low complexity
wago CWE-200
5.3
2021-05-13 CVE-2021-20994 Cross-site Scripting vulnerability in Wago products
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.
network
low complexity
wago CWE-79
6.1