PT-2021-20562 · Wago · Wago 750-881+3

Uwe Disch

·

Published

2021-08-31

·

Updated

2021-09-09

·

CVE-2021-34581

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: WAGO 750-831/xxx-xxx versions FW4 through FW15 WAGO 750-880/xxx-xxx versions FW4 through FW15 WAGO 750-881 versions FW4 through FW15 WAGO 750-889 versions FW4 through FW15
Description: The issue is related to a Missing Release of Resource after Effective Lifetime vulnerability in the OpenSSL implementation. This allows an unauthenticated attacker to cause a Denial of Service (DoS) on the device.
Recommendations: For WAGO 750-831/xxx-xxx versions FW4 through FW15, update to a version later than FW15 to resolve the issue. For WAGO 750-880/xxx-xxx versions FW4 through FW15, update to a version later than FW15 to resolve the issue. For WAGO 750-881 versions FW4 through FW15, update to a version later than FW15 to resolve the issue. For WAGO 750-889 versions FW4 through FW15, update to a version later than FW15 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34581

Affected Products

Wago 750-831
Wago 750-880
Wago 750-881
Wago 750-889