PT-2012-5631 · Wago · Wago I/O System 758
Published
2012-09-07
·
Updated
2013-10-11
·
CVE-2012-4879
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WAGO I/O System 758 model versions 758-870, 758-874, 758-875, and 758-876
Description
The issue concerns default passwords for various accounts on the WAGO I/O System 758 model devices, making it easier for remote attackers to gain login access via a TELNET session. The default passwords are 'wago' for the root and admin accounts, 'user' for the user account, and 'guest' for the guest account.
Recommendations
For versions 758-870, 758-874, 758-875, and 758-876, change the default passwords for the root, admin, user, and guest accounts to unique and secure passwords to prevent unauthorized access.
As a temporary workaround, consider disabling TELNET sessions until secure passwords are set for all default accounts.
Restrict access to the devices to minimize the risk of exploitation by unauthorized users.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago I/O System 758