CVE-2018-12981
Summary
| CVE | CVE-2018-12981 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-12 18:29:00 UTC |
| Updated | 2021-05-20 20:09:00 UTC |
| Description | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Wago | 762-3000 | - | All | All | All |
| Operating System | Wago | 762-3000 Firmware | All | All | All | All |
| Hardware | Wago | 762-3001 | - | All | All | All |
| Operating System | Wago | 762-3001 Firmware | All | All | All | All |
| Hardware | Wago | 762-3002 | - | All | All | All |
| Operating System | Wago | 762-3002 Firmware | All | All | All | All |
| Hardware | Wago | 762-3003 | - | All | All | All |
| Operating System | Wago | 762-3003 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3000 | - | All | All | All |
| Operating System | Wago | E!display 762-3000 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3001 | - | All | All | All |
| Operating System | Wago | E!display 762-3001 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3002 | - | All | All | All |
| Operating System | Wago | E!display 762-3002 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3003 | - | All | All | All |
| Operating System | Wago | E!display 762-3003 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3000 | - | All | All | All |
| Hardware | Wago | E!display 762-3000 | - | All | All | All |
| Operating System | Wago | E!display 762-3000 Firmware | All | All | All | All |
| Operating System | Wago | E!display 762-3000 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3001 | - | All | All | All |
| Hardware | Wago | E!display 762-3001 | - | All | All | All |
| Operating System | Wago | E!display 762-3001 Firmware | All | All | All | All |
| Operating System | Wago | E!display 762-3001 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3002 | - | All | All | All |
| Hardware | Wago | E!display 762-3002 | - | All | All | All |
| Operating System | Wago | E!display 762-3002 Firmware | All | All | All | All |
| Operating System | Wago | E!display 762-3002 Firmware | All | All | All | All |
| Hardware | Wago | E!display 762-3003 | - | All | All | All |
| Hardware | Wago | E!display 762-3003 | - | All | All | All |
| Operating System | Wago | E!display 762-3003 Firmware | All | All | All | All |
| Operating System | Wago | E!display 762-3003 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WAGO Multiple vulnerabilities in e!DISPLAY products — English (USA) | MISC | cert.vde.com | Third Party Advisory |
| Remote code execution via multiple attack vectors in WAGO e!DISPLAY 7300T – SEC Consult | MISC | www.sec-consult.com | Exploit, Third Party Advisory |
| WAGO e!DISPLAY Web-Based-Management | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.wago.com/medias/SA-WBM-2018-004.pdf | CONFIRM | www.wago.com | Third Party Advisory |
| Full Disclosure: SEC Consult SA-20180711-0 :: Remote code execution via multiple attack vectors in WAGO e!DISPLAY 7300T | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| WAGO e!DISPLAY 7300T - Multiple Vulnerabilities | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590458 WAGO e!DISPLAY Web-Based-Management Multiple Vulnerabilities (ICSA-18-198-02)