Note:
This project will be discontinued after December 13, 2021. [more]
Product:
750\-885_firmware
(Wago)| Repositories |
Unknown: This might be proprietary software. |
| #Vulnerabilities | 24 |
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2019-05-07 | CVE-2019-10712 | The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access. | 750\-330_firmware, 750\-352_firmware, 750\-829_firmware, 750\-830_firmware, 750\-831_firmware, 750\-849_firmware, 750\-852_firmware, 750\-871_firmware, 750\-872_firmware, 750\-873_firmware, 750\-880_firmware, 750\-881_firmware, 750\-882_firmware, 750\-884_firmware, 750\-885_firmware, 750\-889_firmware | 9.8 | ||
| 2020-12-10 | CVE-2020-12516 | Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack. | 750\-331_firmware, 750\-352_firmware, 750\-829_firmware, 750\-831_firmware, 750\-852_firmware, 750\-880_firmware, 750\-881_firmware, 750\-882_firmware, 750\-885_firmware, 750\-889_firmware | 7.5 | ||
| 2020-09-30 | CVE-2020-12505 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx, WAGO 750-881, WAGO 750-831/xxx-xxx, WAGO 750-882, WAGO 750-885/xxx-xxx, WAGO 750-889 in versions FW07 and below. | 750\-831_firmware, 750\-852_firmware, 750\-880_firmware, 750\-881_firmware, 750\-882_firmware, 750\-885_firmware, 750\-889_firmware | 9.1 | ||
| 2018-04-03 | CVE-2018-8836 | Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools. | 750\-829_firmware, 750\-831_firmware, 750\-852_firmware, 750\-880_firmware, 750\-881_firmware, 750\-882_firmware, 750\-885_firmware, 750\-889_firmware | 5.3 |