CVE-2021-34581: WAGO: Denial of Service vulnerability inside the OpenSSL implementation
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-34581.
What is the title of the vulnerability?
The title of the vulnerability is 'Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO...'
What is the severity of CVE-2021-34581?
The severity of CVE-2021-34581 is high with a severity value of 7.5.
Which software versions are affected by CVE-2021-34581?
Versions FW4 up to FW15 of Wago 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 are affected by CVE-2021-34581.
How can an unauthenticated attacker exploit CVE-2021-34581?
An unauthenticated attacker can exploit CVE-2021-34581 to cause a Denial of Service (DoS) on the device.
Where can I find more information about CVE-2021-34581?
You can find more information about CVE-2021-34581 at the following reference: https://cert.vde.com/en-us/advisories/vde-2021-038