Vulnerabilidades em WAGO

98 resultados
Análise Vexday

Com 64 CVEs catalogadas, o portfólio de vulnerabilidades da WAGO apresenta 20 entradas de severidade crítica — um volume que exige atenção contínua em ambientes de tecnologia operacional. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores de ameaça no momento, o que oferece uma janela para priorização proativa de remediações. O ponto de maior preocupação imediata é CVE-2023-1698, com escore EPSS de 0,8191, indicando alta probabilidade estatística de exploração — essa falha merece tratamento prioritário independentemente da ausência de registro formal no KEV. O tipo de fraqueza mais recorrente, CWE-306 (ausência de autenticação para função crítica), é especialmente relevante em contextos industriais onde o acesso não autenticado a funções de controle pode ter consequências físicas diretas.

CVE-2019-5172An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.0EPSS 1.3%CVE-2019-5168An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14).EPSS 1.3%CVE-2020-12505HIGHWAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07EPSS 1.2%CVE-2019-5167An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14).EPSS 1.2%CVE-2019-5158An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation softwarEPSS 1.1%CVE-2021-21001CRITICALWAGO: PFC200 Access to files outside the home directoryEPSS 1.1%CVE-2019-5107A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker withEPSS 1.1%CVE-2023-4149CRITICALWAGO: OS Command Injection Vulnerability in Managed SwitchEPSS 1.1%CVE-2021-20998CRITICALWAGO: Managed Switches: Unauthorized creation of user accountsEPSS 1.1%CVE-2022-45140CRITICALWAGO: Missing Authentication for Critical Function EPSS 1.1%CVE-2019-5135An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web applicationEPSS 1.0%CVE-2021-21000MEDIUMWAGO: PFC200 Denial of Service due to the number of connections to the runtimeEPSS 1.0%CVE-2023-5188HIGHWAGO Improper Input Validation in IEC61850 Server / TelecontrolEPSS 1.0%CVE-2021-34566CRITICALWAGO I/O-Check Service prone to Memory OverflowEPSS 1.0%CVE-2021-34568HIGHWAGO I/O-Check Service prone to Allocation of Resources Without Limits or ThrottlingEPSS 1.0%CVE-2021-34581HIGHWAGO: Denial of Service vulnerability inside the OpenSSL implementationEPSS 1.0%CVE-2021-20997HIGHWAGO: Managed Switches: Unauthorized access to password hashesEPSS 1.0%CVE-2021-34578CRITICALWAGO: Authentication Vulnerability in Web-Based ManagementEPSS 1.0%CVE-2023-1150HIGHWAGO: Series 750-3x/-8x prone to MODBUS server DoSEPSS 0.9%CVE-2022-3843CRITICALWAGO: Exposure of configuration interface in unmanaged switchesEPSS 0.9%