First published: Mon May 24 2021(Updated: )
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
WAGO 750-823 firmware | <=fw07 | |
WAGO 750-823 firmware | ||
WAGO 750-829 firmware | <=fw14 | |
WAGO 750-829 firmware | ||
WAGO Ethernet Firmware | <=fw14 | |
WAGO 750-831 firmware | ||
WAGO 750-832/000-002 firmware | <=fw06 | |
WAGO 750-xxx series firmware | ||
WAGO 750-852 firmware | <=fw14 | |
WAGO 750-xxx series firmware | ||
WAGO 750-862 firmware | <=fw07 | |
WAGO 750-xxx series firmware | ||
WAGO 750-880/040-000 firmware | <=fw15 | |
WAGO 750-880/040-000 | ||
WAGO Ethernet Firmware | <=fw14 | |
WAGO 750-881 firmware | ||
WAGO 750-882 firmware | <=fw14 | |
WAGO 750-882 firmware | ||
WAGO 750-885 firmware | <=fw14 | |
WAGO 750-885 firmware | ||
WAGO 750-889 firmware | <=fw14 | |
WAGO 750-889 firmware | ||
WAGO 750-890 Firmware | <=fw07 | |
WAGO 750-890 firmware | ||
WAGO 750-891 firmware | <=fw07 | |
WAGO 750-891 firmware | ||
WAGO Ethernet Firmware | <=fw07 | |
WAGO 750-893 firmware | ||
WAGO 750-8202/025-002 Firmware | <03.06.19_\(18\) | |
WAGO 750-8202 Firmware | ||
WAGO Ethernet Firmware | <03.06.19_\(18\) | |
WAGO 750-8203 firmware | ||
WAGO 750-8204 firmware | <03.06.19_\(18\) | |
WAGO 750-8204/025-000 | ||
WAGO 750-8206 firmware | <03.06.19_\(18\) | |
WAGO 750-xxx series firmware | ||
WAGO 750-8207 firmware | <03.06.19_\(18\) | |
WAGO 750-8207/025-000 | ||
WAGO 750-8208/025-001 firmware | <03.06.19_\(18\) | |
WAGO 750-xxx series firmware | ||
WAGO 750-8210/040-000 firmware | <03.06.19_\(18\) | |
WAGO 750-8210 firmware | ||
WAGO 750-8211/040-001 firmware | <03.06.19_\(18\) | |
WAGO 750-8211/040-000 | ||
WAGO 750-8212/025-002 firmware | <03.06.19_\(18\) | |
Cisco 8212 | ||
WAGO 750-8213/040-010 firmware | <03.06.19_\(18\) | |
WAGO 750-8213/040-010 | ||
WAGO 750-8214 firmware | <03.06.19_\(18\) | |
WAGO 750-8214 firmware | ||
WAGO 750-8216 firmware | <03.06.19_\(18\) | |
WAGO 750-8216/040-000 | ||
WAGO 750-8217 firmware | <03.06.19_\(18\) | |
WAGO 750-8217 firmware |
WAGO recommends all effected users with CODESYS 2.3 Runtime PLCs to update to the firmware versions listed at https://cert.vde.com/en-us/advisories/vde-2021-014 in the solution paragraph.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-21001.
The severity of CVE-2021-21001 is critical with a severity value of 6.5.
WAGO PFC200 devices in different firmware versions are affected by CVE-2021-21001.
An authorized attacker with network access to the WAGO PFC200 device can exploit CVE-2021-21001 by using specially crafted packets to access the file system with higher privileges.
It is recommended to update the firmware of the WAGO PFC200 device to a version that is not vulnerable to CVE-2021-21001.