First published: Tue Apr 03 2018(Updated: )
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Wago 750-880 Firmware | <=10 | |
WAGO 750-880 | ||
Wago 750-881 Firmware | <=10 | |
WAGO 750-881 | ||
Wago 750-852 Firmware | <=10 | |
WAGO 750-852 | ||
Wago 750-882 Firmware | <=10 | |
WAGO 750-882 | ||
Wago 750-885 Firmware | <=10 | |
WAGO 750-885 | ||
Wago 750-831 Firmware | <=10 | |
WAGO 750-831 | ||
Wago 750-889 Firmware | <=10 | |
WAGO 750-889 | ||
Wago 750-829 Firmware | <=10 | |
Wago 750-829 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8836 is a vulnerability that affects Wago 750 Series PLCs with firmware version 10 and prior.
The severity of CVE-2018-8836 is medium with a score of 5.3.
CVE-2018-8836 affects the communications with commission and service tools, specifically the TCP connection, due to an improper implementation of the 3-way handshake.
Wago 750 Series PLCs with firmware version 10 and prior are affected by CVE-2018-8836.
To fix CVE-2018-8836, users should update their Wago 750 Series PLC firmware to a version higher than 10.