Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
2018-04-03T13:29:00.277
2024-11-21T04:14:25.160
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | wago | 750-880_firmware | ≤ 10 | Yes |
Hardware | wago | 750-880 | - | No |
Operating System | wago | 750-881_firmware | ≤ 10 | Yes |
Hardware | wago | 750-881 | - | No |
Operating System | wago | 750-852_firmware | ≤ 10 | Yes |
Hardware | wago | 750-852 | - | No |
Operating System | wago | 750-882_firmware | ≤ 10 | Yes |
Hardware | wago | 750-882 | - | No |
Operating System | wago | 750-885_firmware | ≤ 10 | Yes |
Hardware | wago | 750-885 | - | No |
Operating System | wago | 750-831_firmware | ≤ 10 | Yes |
Hardware | wago | 750-831 | - | No |
Operating System | wago | 750-889_firmware | ≤ 10 | Yes |
Hardware | wago | 750-889 | - | No |
Operating System | wago | 750-829_firmware | ≤ 10 | Yes |
Hardware | wago | 750-829 | - | No |