CVE-2020-12506: WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-12506.
What is the severity level of CVE-2020-12506?
The severity level of CVE-2020-12506 is critical with a score of 9.1.
Which devices are affected by CVE-2020-12506?
The devices affected by CVE-2020-12506 include WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832, WAGO 750-862, WAGO 750-891, and WAGO 750-890 with firmware versions up to and including FW03.
What is the impact of CVE-2020-12506?
CVE-2020-12506 allows an attacker to change the settings of the WAGO 750-8XX series devices without authentication.
How can I mitigate CVE-2020-12506?
To mitigate CVE-2020-12506, update the firmware of the affected WAGO devices to a version higher than FW03.