CVE-2021-20997: WAGO: Managed Switches: Unauthorized access to password hashes
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-20997.
What is the severity of CVE-2021-20997?
The severity of CVE-2021-20997 is high (7.5).
Which software versions are affected by CVE-2021-20997?
The software versions affected by CVE-2021-20997 are Wago 0852-0303 Firmware (up to version 1.2.3.s0), Wago 0852-1305 Firmware (up to version 1.1.7.s0), Wago 0852-1505 Firmware (up to version 1.1.6.s0), Wago 0852-1305/000-001 Firmware (up to version 1.0.4.s0), and Wago 0852-1505/000-001 Firmware (up to version 1.0.4.s0).
What is the description of CVE-2021-20997?
The description of CVE-2021-20997 is that in multiple managed switches by WAGO in different versions, it is possible to read out the password hashes of all Web-based Management users.
How can CVE-2021-20997 be fixed?
To fix CVE-2021-20997, it is recommended to apply the latest firmware update provided by WAGO and follow any additional recommendations or patches provided by the vendor.