PT-2020-5126 · Wago · Wago 750-8Xx Series+7
Maxim Rupp
·
Published
2020-09-30
·
Updated
2021-11-17
·
CVE-2020-12505
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WAGO 750-8XX series versions FW07 and prior versions
WAGO 750-852 versions FW07 and prior versions
WAGO 750-880/xxx-xxx versions FW07 and prior versions
WAGO 750-881 versions FW07 and prior versions
WAGO 750-831/xxx-xxx versions FW07 and prior versions
WAGO 750-882 versions FW07 and prior versions
WAGO 750-885/xxx-xxx versions FW07 and prior versions
WAGO 750-889 versions FW07 and prior versions
Description
The issue is related to improper authentication in the WAGO ethernet controller, allowing a remote attacker to change some special parameters without authentication. This can be exploited by an attacker to modify certain settings.
Recommendations
For WAGO 750-8XX series versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-852 versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-880/xxx-xxx versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-881 versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-831/xxx-xxx versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-882 versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-885/xxx-xxx versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
For WAGO 750-889 versions FW07 and prior versions, update to a version above FW07 to resolve the issue.
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wago 750-831
Wago 750-852
Wago 750-880
Wago 750-881
Wago 750-882
Wago 750-885
Wago 750-889
Wago 750-8Xx Series