QID 590460

Date Published: 2021-10-14

QID 590460: WAGO Ethernet Web-based Management Authentication Bypass Vulnerability Vulnerability (ICSA-16-357-02)

AFFECTED PRODUCTS
WAGO reports that the vulnerability affects the following products:
WAGO 750-8202/PFC200 prior to FW04 (released August 2015),
WAGO 750-881 prior to FW09 (released August 2016), and
WAGO 0758-0874-0000-0111

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker who exploits this vulnerability could be able to view and edit settings without authenticating.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-16-357-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590460

    Software Advisories
    Advisory ID Software Component Link
    ICSA-16-357-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-16-357-02