WAGO Edge Controller等都是德国万可(WAGO)公司的产品。WAGO Edge Controller是一个边缘控制器。WAGO PFC是一款用于模块化 WAGO-I/O 系统的紧凑型 PLC。WAGO CC100 0751-9x01是一款紧凑型控制器。 WAGO多款产品存在路径遍历漏洞,该漏洞源于低权限远程攻击者可以覆盖文件系统上的任意文件,从而导致拒绝服务和数据丢失。以下产品受到影响:WAGO CC100 0751-9x01、WAGO Edge Controller 0752-8303
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WAGO | CC100 0751-9x01 | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC100 G2 0750-811x-xxxx-xxxx | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC200 G2 750-821x-xxx-xxx | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-420x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-430x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-520x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-530x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-620x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-630x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | Edge Controller 0752-8303/8000-0002 | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC200 G2 0750-821x/xxx-xxx | 0.0.0 ~ 04.04.03 (70) | - |
|
| WAGO | CC100 0751/9x01 | 0.0.0 ~ 04.03.03 (72) | - |
|
| WAGO | CC100 0751/9x01 | 0.0.0 ~ 04.04.03 (70) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-41969 | 8.8 HIGH | WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple Devices |
| CVE-2024-41967 | 8.1 HIGH | WAGO: Boot Mode Manipulation in Multiple Devices |
| CVE-2024-41973 | 8.1 HIGH | WAGO: Remote Arbitrary File Write with Root Privileges in multiple Devices |
| CVE-2024-41974 | 7.1 HIGH | WAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple |
| CVE-2024-41972 | 6.5 MEDIUM | WAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple Devices |
| CVE-2024-41970 | 5.7 MEDIUM | WAGO: Unauthorized Diagnostic Data Exposure in Multiple Devices |
| CVE-2024-41968 | 5.4 MEDIUM | WAGO: Docker Settings Manipulation in Multiple Devices |
No comments yet