Vulnerabilities > Wago > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-13 CVE-2021-20996 Incorrect Permission Assignment for Critical Resource vulnerability in Wago products
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
network
low complexity
wago CWE-732
5.3
2020-03-12 CVE-2019-5177 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14).
local
low complexity
wago CWE-787
5.5
2020-03-12 CVE-2019-5176 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14).
local
low complexity
wago CWE-787
5.5
2020-03-11 CVE-2019-5182 Out-of-bounds Write vulnerability in Wago Pfc200 Firmware 03.02.02(14)
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14).
local
low complexity
wago CWE-787
5.5
2020-03-11 CVE-2019-5135 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Wago Pfc100 Firmware and Pfc200 Firmware
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers.
network
low complexity
wago CWE-327
5.3
2020-03-11 CVE-2019-5106 Use of Hard-coded Credentials vulnerability in Wago E!Cockpit 1.5.1.1
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1.
local
low complexity
wago CWE-798
5.5
2019-12-18 CVE-2019-5073 Information Exposure vulnerability in Wago PFC 100 Firmware and PFC 200 Firmware
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12).
network
low complexity
wago CWE-200
5.3
2019-10-19 CVE-2019-18202 Unspecified vulnerability in Wago PFC Firmware
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control.
network
low complexity
wago
5.3
2018-10-12 CVE-2018-16210 Cross-site Scripting vulnerability in Wago 750-881 Ethernet Controller Devices Firmware 01.08.01(10)/01.09.18(13)
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
network
low complexity
wago CWE-79
6.1
2018-07-12 CVE-2018-12981 Cross-site Scripting vulnerability in Wago products
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02.
network
low complexity
wago CWE-79
5.4