CVE-2021-20998: WAGO: Managed Switches: Unauthorized creation of user accounts
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is vulnerability CVE-2021-20998?
Vulnerability CVE-2021-20998 is a vulnerability found in multiple managed switches by WAGO, which allows the creation of users without authorization and with specially crafted packets.
What is the severity of CVE-2021-20998?
The severity of vulnerability CVE-2021-20998 is rated as critical with a severity value of 9.8.
Which software versions are affected by CVE-2021-20998?
The software versions affected by vulnerability CVE-2021-20998 are: Wago 0852-0303 Firmware (up to version 1.2.3.s0), Wago 0852-1305 Firmware (up to version 1.1.7.s0), Wago 0852-1505 Firmware (up to version 1.1.6.s0), Wago 0852-1305/000-001 Firmware (up to version 1.0.4.s0), and Wago 0852-1505/000-001 Firmware (up to version 1.0.4.s0).
How can the vulnerability CVE-2021-20998 be exploited?
Vulnerability CVE-2021-20998 can be exploited by sending specially crafted packets to the affected managed switches by WAGO.
Is Wago 0852-0303 vulnerable to CVE-2021-20998?
Yes, Wago 0852-0303 is vulnerable to CVE-2021-20998 up to version 1.2.3.s0.