CVE-2021-34578: WAGO: Authentication Vulnerability in Web-Based Management
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34578?
The severity of CVE-2021-34578 is critical, with a score of 8.1.
How does CVE-2021-34578 affect WAGO PLCs?
CVE-2021-34578 allows an attacker with access to the WBM to read and write settings-parameters of the device without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Which WAGO PLCs are affected by CVE-2021-34578?
CVE-2021-34578 affects WAGO PLC models 750-890/040-000, 750-890/025-001, 750-890/025-002, 750-890/025-000, 750-832/000-002, 750-362, 750-823, 750-832, 750-363, 750-862, 750-891, and 750-893 in firmware versions up to FW07.
How can CVE-2021-34578 be fixed?
To fix CVE-2021-34578, it is recommended to update the firmware of the affected WAGO PLC models to a version beyond FW07.
Where can I find more information about CVE-2021-34578?
More information about CVE-2021-34578 can be found at the following reference link: https://cert.vde.com/en-us/advisories/vde-2020-044