CVE-2018-8836: Medium severity WAGO 750-880 Firmware vulnerability

Published Apr 3, 2018
·
Updated

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Affected Software

32 affected components
WAGO 750-880 Firmware<=10
WAGO 750-880
WAGO 750-881 Firmware<=10
WAGO 750-881
WAGO 750-852 Firmware<=10
WAGO 750-852
WAGO 750-882 Firmware<=10
WAGO 750-882
WAGO 750-885 Firmware<=10
WAGO 750-885
WAGO 750-831 Firmware<=10
WAGO 750-831
WAGO 750-889 Firmware<=10
WAGO 750-889
WAGO 750-829 Firmware<=10
WAGO 750-829
All of the following
WAGO 750-880 Firmware<=10
WAGO 750-880
All of the following
WAGO 750-881 Firmware<=10
WAGO 750-881
All of the following
WAGO 750-852 Firmware<=10
WAGO 750-852
All of the following
WAGO 750-882 Firmware<=10
WAGO 750-882
All of the following
WAGO 750-885 Firmware<=10
WAGO 750-885
All of the following
WAGO 750-831 Firmware<=10
WAGO 750-831
All of the following
WAGO 750-889 Firmware<=10
WAGO 750-889
All of the following
WAGO 750-829 Firmware<=10
WAGO 750-829

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Wago 750 Series PLCs to a version that resolves this vulnerability.

    Fixed in 10

Event History

Apr 3, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2018-8836?

CVE-2018-8836 is a vulnerability that affects Wago 750 Series PLCs with firmware version 10 and prior.

2

What is the severity of CVE-2018-8836?

The severity of CVE-2018-8836 is medium with a score of 5.3.

3

How does CVE-2018-8836 affect Wago 750 Series PLCs?

CVE-2018-8836 affects the communications with commission and service tools, specifically the TCP connection, due to an improper implementation of the 3-way handshake.

4

What software is affected by CVE-2018-8836?

Wago 750 Series PLCs with firmware version 10 and prior are affected by CVE-2018-8836.

5

How can I fix CVE-2018-8836?

To fix CVE-2018-8836, users should update their Wago 750 Series PLC firmware to a version higher than 10.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203