WAGO: Unauthorized Diagnostic Data Exposure in Multiple Devices
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.7epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected products
WAGO · CC100 0751-9x01WAGO · CC100 0751/9x01WAGO · Edge Controller 0752-8303/8000-0002WAGO · PFC100 G2 0750-811x-xxxx-xxxxWAGO · PFC200 G2 0750-821x/xxx-xxxWAGO · PFC200 G2 750-821x-xxx-xxxWAGO · TP600 0762-420x/8000-000xWAGO · TP600 0762-430x/8000-000xWAGO · TP600 0762-520x/8000-000xWAGO · TP600 0762-530x/8000-000xWAGO · TP600 0762-620x/8000-000xWAGO · TP600 0762-630x/8000-000x