CVE-2024-41969: WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple Devices
Published Nov 18, 2024
·Updated
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.
Affected Software
1 affected component
Wago CODESYS V3
Event History
Nov 18, 2024
CVE Published
via MITRE·09:04 AM
Data Sourced
via MITRE·09:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-41969?
CVE-2024-41969 is classified as a low-severity vulnerability.
2
How do I fix CVE-2024-41969?
To fix CVE-2024-41969, ensure that proper authentication measures are implemented in the CODESYS V3 service.
3
What systems are affected by CVE-2024-41969?
CVE-2024-41969 affects the WAGO CODESYS V3 service.
4
Can CVE-2024-41969 lead to remote access?
Yes, CVE-2024-41969 allows low-privileged remote attackers to gain full system access.
5
What impact does CVE-2024-41969 have on system availability?
CVE-2024-41969 can potentially lead to a denial of service (DoS) condition.