PT-2021-20562 · Wago · Wago 750-881+3
Uwe Disch
·
Published
2021-08-31
·
Updated
2021-09-09
·
CVE-2021-34581
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
WAGO 750-831/xxx-xxx versions FW4 through FW15
WAGO 750-880/xxx-xxx versions FW4 through FW15
WAGO 750-881 versions FW4 through FW15
WAGO 750-889 versions FW4 through FW15
Description:
The issue is related to a Missing Release of Resource after Effective Lifetime vulnerability in the OpenSSL implementation. This allows an unauthenticated attacker to cause a Denial of Service (DoS) on the device.
Recommendations:
For WAGO 750-831/xxx-xxx versions FW4 through FW15, update to a version later than FW15 to resolve the issue.
For WAGO 750-880/xxx-xxx versions FW4 through FW15, update to a version later than FW15 to resolve the issue.
For WAGO 750-881 versions FW4 through FW15, update to a version later than FW15 to resolve the issue.
For WAGO 750-889 versions FW4 through FW15, update to a version later than FW15 to resolve the issue.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago 750-831
Wago 750-880
Wago 750-881
Wago 750-889