Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

0852 1328 Firmware CRITICAL 9.8
CVE-2025-41732

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buf…

Fix: 02.64+
Fix from $2,300 2025-12-10
0852 1328 Firmware CRITICAL 9.8
CVE-2025-41730

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack bu…

Fix: 02.64+
Fix from $2,300 2025-12-10
Telecontrol Configurator HIGH 7.5
CVE-2023-5188

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An…

Fix: 1.4.6.0+
Fix from $1,950 2023-12-05
0852 0602 Firmware CRITICAL 9.8
CVE-2023-4149

A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system contro…

Fix: 1.0.6.s0 / 1.2.5.s0+
Fix from $2,300 2023-11-21
Compact Controller 100 Firmware MEDIUM 5.3
CVE-2023-3379

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non…

Fix: 22+
Fix from $1,600 2023-11-20
750 363\/040 000 Firmware HIGH 7.5
CVE-2023-1150

Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with speci…

Mitigation only
Fix from $1,950 2023-06-26
Compact Controller 100 Firmware CRITICAL 9.8
CVE-2023-1698EPSS 82%

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which…

Fix: after 23
Fix from $2,300 2023-05-15
751 9301 Firmware CRITICAL 9.8
CVE-2022-45138

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use t…

Fix: 22+
Fix from $2,300 2023-02-27
751 9301 Firmware CRITICAL 9.8
CVE-2022-45140

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthentic…

Fix: 22+
Fix from $2,300 2023-02-27
751 9301 Firmware MEDIUM 6.1
CVE-2022-45137

The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. T…

Fix: 22+
Fix from $1,600 2023-02-27
751 9301 Firmware MEDIUM 5.3
CVE-2022-45139

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. …

Fix: 22+
Fix from $1,600 2023-02-27
852 111\/000 001 Firmware CRITICAL 9.1
CVE-2022-3843

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote atta…

Mitigation only
Fix from $2,300 2023-02-16
Pfc100 Firmware MEDIUM 5.9
CVE-2022-3738

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive informa…

Fix: after 22
Fix from $1,600 2023-01-19
750 8100 Firmware CRITICAL 9.8
CVE-2021-34569

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool an…

Fix: 18+
Fix from $2,300 2022-11-09
750 8100 Firmware HIGH 7.5
CVE-2021-34568

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo…

Fix: 18+
Fix from $1,950 2022-11-09
750 8100 Firmware HIGH 8.2
CVE-2021-34567

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo…

Fix: 18+
Fix from $1,950 2022-11-09
750 8100 Firmware CRITICAL 9.1
CVE-2021-34566

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash…

Fix: 18+
Fix from $2,300 2022-11-09
750 8100 Firmware HIGH 7.5
CVE-2022-3281

WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Addre…

Fix: after 03.10.08
Fix from $1,950 2022-10-17
750 8100 Firmware MEDIUM 5.4
CVE-2022-22511

Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges…

Mitigation only
Fix from $1,600 2022-03-09
750 823 Firmware HIGH 8.1
CVE-2021-34595

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior t…

Mitigation only
Fix from $1,950 2021-10-26
750 8202 Firmware HIGH 7.5
CVE-2021-34593

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several den…

No fix yet
Fix from $1,950 2021-10-26
750 823 Firmware MEDIUM 6.5
CVE-2021-34596

A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7…

Mitigation only
Fix from $1,600 2021-10-26
750 823 Firmware CRITICAL 9.1
CVE-2021-34584

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the …

No fix yet
Fix from $2,300 2021-10-26
750 8214 Firmware HIGH 7.5
CVE-2021-34583EPSS 8%

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the C…

No fix yet
Fix from $1,950 2021-10-26
750 823 Firmware HIGH 7.5
CVE-2021-34585

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under …

No fix yet
Fix from $1,950 2021-10-26
750 823 Firmware HIGH 7.5
CVE-2021-34586EPSS 13%

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may re…

No fix yet
Fix from $1,950 2021-10-26
750 890\/040 000 Firmware HIGH 8.1
CVE-2021-34578

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically construct…

Mitigation only
Fix from $1,950 2021-08-31
750 880\/040 000 Firmware HIGH 7.5
CVE-2021-34581

Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-8…

Mitigation only
Fix from $1,950 2021-08-31
750 893 Firmware CRITICAL 9.8
CVE-2021-30188

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

Mitigation only
Fix from $2,300 2021-05-25
750 893 Firmware CRITICAL 9.8
CVE-2021-30189

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

Mitigation only
Fix from $2,300 2021-05-25