Vulnerabilities (CVE)

Filtered by vendor Wago Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3379 1 Wago 14 Compact Controller 100, Compact Controller 100 Firmware, Edge Controller and 11 more 2023-11-30 N/A N/A
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
CVE-2023-4149 1 Wago 6 0852-0602, 0852-0602 Firmware, 0852-0603 and 3 more 2023-11-29 N/A N/A
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based management.
CVE-2012-4879 1 Wago 1 Wago I\/o System 758 Industrial Pc Device 2013-10-11 10.0 HIGH N/A
The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest for the guest account, which makes it easier for remote attackers to obtain login access via a TELNET session, a different vulnerability than CVE-2012-3013.
CVE-2012-3013 1 Wago 1 Wago I\/o System 758 Industrial Pc Device 2013-10-08 10.0 HIGH N/A
WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session.