CVE-2018-8836: Medium severity WAGO 750-880 Firmware vulnerability
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wago 750 Series PLCsto a version that resolves this vulnerability.Fixed in 10
Event History
Frequently Asked Questions
What is CVE-2018-8836?
CVE-2018-8836 is a vulnerability that affects Wago 750 Series PLCs with firmware version 10 and prior.
What is the severity of CVE-2018-8836?
The severity of CVE-2018-8836 is medium with a score of 5.3.
How does CVE-2018-8836 affect Wago 750 Series PLCs?
CVE-2018-8836 affects the communications with commission and service tools, specifically the TCP connection, due to an improper implementation of the 3-way handshake.
What software is affected by CVE-2018-8836?
Wago 750 Series PLCs with firmware version 10 and prior are affected by CVE-2018-8836.
How can I fix CVE-2018-8836?
To fix CVE-2018-8836, users should update their Wago 750 Series PLC firmware to a version higher than 10.