CVE-2021-20996: WAGO: Managed Switches: Unsecure Cookie settings
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-20996?
CVE-2021-20996 is a vulnerability found in multiple managed switches by WAGO, where specially crafted requests can lead to cookies being transferred to third parties.
Which WAGO managed switches are affected by CVE-2021-20996?
The Wago 0852-0303, 0852-1305, 0852-1505, 0852-1305/000-001, and 0852-1505/000-001 managed switches are affected by CVE-2021-20996.
What is the severity of CVE-2021-20996?
The severity of CVE-2021-20996 is medium, with a severity value of 5.3.
How can CVE-2021-20996 be exploited?
CVE-2021-20996 can be exploited by sending specially crafted requests to the affected WAGO managed switches, which can lead to cookies being transferred to third parties.
Is there a fix for CVE-2021-20996?
At the moment, there is no fix available for CVE-2021-20996. It is recommended to follow any recommendations provided by the vendor or security advisories.