CWE
404
Advisory Published
Updated

CVE-2018-8836

First published: Tue Apr 03 2018(Updated: )

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Wago 750-880 Firmware<=10
WAGO 750-880
Wago 750-881 Firmware<=10
WAGO 750-881
Wago 750-852 Firmware<=10
WAGO 750-852
Wago 750-882 Firmware<=10
WAGO 750-882
Wago 750-885 Firmware<=10
WAGO 750-885
Wago 750-831 Firmware<=10
WAGO 750-831
Wago 750-889 Firmware<=10
WAGO 750-889
Wago 750-829 Firmware<=10
Wago 750-829

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2018-8836?

    CVE-2018-8836 is a vulnerability that affects Wago 750 Series PLCs with firmware version 10 and prior.

  • What is the severity of CVE-2018-8836?

    The severity of CVE-2018-8836 is medium with a score of 5.3.

  • How does CVE-2018-8836 affect Wago 750 Series PLCs?

    CVE-2018-8836 affects the communications with commission and service tools, specifically the TCP connection, due to an improper implementation of the 3-way handshake.

  • What software is affected by CVE-2018-8836?

    Wago 750 Series PLCs with firmware version 10 and prior are affected by CVE-2018-8836.

  • How can I fix CVE-2018-8836?

    To fix CVE-2018-8836, users should update their Wago 750 Series PLC firmware to a version higher than 10.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203