WAGO PFC100等都是德国万可(WAGO)公司的产品。WAGO PFC100是一款可编程逻辑控制器(PLC)。WAGO CC100 0751-9x01是一款紧凑型控制器。WAGO Edge Controller 0752-8303/8000-0002是一款控制器。 WAGO多款产品存在安全漏洞,该漏洞源于低权限远程攻击者可能会由于关键资源的权限分配不正确而修改BACNet服务属性,导致容易受到拒绝服务攻击。以下产品受到影响:WAGO CC100 0751-9x01、WAGO Edge Control
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WAGO | CC100 0751-9x01 | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC100 G2 0750-811x-xxxx-xxxx | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC200 G2 750-821x-xxx-xxx | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-420x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-430x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-520x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-530x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-620x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | TP600 0762-630x/8000-000x | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | Edge Controller 0752-8303/8000-0002 | 0.0.0 ~ 4.5.10 (FW27) | - |
|
| WAGO | PFC200 G2 0750-821x/xxx-xxx | 0.0.0 ~ 04.04.03 (70) | - |
|
| WAGO | CC100 0751/9x01 | 0.0.0 ~ 04.03.03 (72) | - |
|
| WAGO | CC100 0751/9x01 | 0.0.0 ~ 04.04.03 (70) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-41969 | 8.8 HIGH | WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple Devices |
| CVE-2024-41967 | 8.1 HIGH | WAGO: Boot Mode Manipulation in Multiple Devices |
| CVE-2024-41971 | 8.1 HIGH | WAGO: Arbitrary File Overwrite in Multiple Devices |
| CVE-2024-41973 | 8.1 HIGH | WAGO: Remote Arbitrary File Write with Root Privileges in multiple Devices |
| CVE-2024-41972 | 6.5 MEDIUM | WAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple Devices |
| CVE-2024-41970 | 5.7 MEDIUM | WAGO: Unauthorized Diagnostic Data Exposure in Multiple Devices |
| CVE-2024-41968 | 5.4 MEDIUM | WAGO: Docker Settings Manipulation in Multiple Devices |
No comments yet