<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_wagogmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:00:59 +0000</lastBuildDate>
    <item>
      <title>VDE-2018-010 — WAGO: Multiple vulnerabilities in e!DISPLAY products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-010</link>
      <description>&lt;p&gt;An unauthenticated user can exploit a vulnerability (CVE-2018-12981) to inject code in the WBM via reflected cross-site scripting (XSS), if he is able trick a user to open a special crafted web site. This could allow an attacker to execute code in the context of the user and execute arbitrary commands with restriction to the permissions of the user. Authenticated users can use a vulnerability to inject code in the WBM via persistent cross-site scripting (XSS) via special crafted requests which will be rendered and/or executed in the browser. Authenticated WBM users can transfer arbitrary files to different file system locations (CVE- 2018-12980) to which the web server has the required permissions and partially allowing replacing existing files due weak file permissions (CVE-2018-12979) which can result in an authentication bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated user can exploit a vulnerability (CVE-2018-12981) to inject code in the WBM via reflected cross-site scripting (XSS), if he is able trick a user to open a special crafted web site. This could allow an attacker to execute code in the context of the user and execute arbitrary commands with restriction to the permissions of the user. Authenticated users can use a vulnerability to inject code in the WBM via persistent cross-site scripting (XSS) via special crafted requests which will be rendered and/or executed in the browser. Authenticated WBM users can transfer arbitrary files to different file system locations (CVE- 2018-12980) to which the web server has the required permissions and partially allowing replacing existing files due weak file permissions (CVE-2018-12979) which can result in an authentication bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-010</guid>
      <pubDate>Tue, 10 Jul 2018 09:50:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-013 — WAGO: 750-8xx Controller Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-013</link>
      <description>&lt;p&gt;The 750-8xx controller are susceptible to a Denial-of-Service attack due to a flood of network packets. Please consult the original paper for details (link at the bottom of this advisory).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The 750-8xx controller are susceptible to a Denial-of-Service attack due to a flood of network packets. Please consult the original paper for details (link at the bottom of this advisory).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-013</guid>
      <pubDate>Fri, 17 Aug 2018 09:45:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-013 — WAGO: Multiple Vulnerabilities in industrial managed switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-013</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO 852-303, 852-1305 and 852-1505 industrial managed ethernet switches.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO 852-303, 852-1305 and 852-1505 industrial managed ethernet switches.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-013</guid>
      <pubDate>Wed, 12 Jun 2019 10:25:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-017 — WAGO: Series PFC100/PFC200 Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-017</link>
      <description>&lt;p&gt;The reported vulnerability allows a remote attacker to check paths and file names that are used in filesystem operations.&lt;/p&gt;
&lt;p&gt;**Update, 18.9.2019, 18:30**&lt;/p&gt;
&lt;p&gt;* fixed typo in modelname, replaced PCF with PFC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The reported vulnerability allows a remote attacker to check paths and file names that are used in filesystem operations.&lt;/p&gt;
&lt;p&gt;**Update, 18.9.2019, 18:30**&lt;/p&gt;
&lt;p&gt;* fixed typo in modelname, replaced PCF with PFC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-017</guid>
      <pubDate>Wed, 18 Sep 2019 11:25:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-022 — WAGO: Multiple Vulnerabilities in I/O-Check Service in Multiple Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-022</link>
      <description>&lt;p&gt;The reported vulnerabilities allow a remote attacker to change the setting, delete the application, set the device to factory defaults, code execution and to cause a system crash or denial of service.&lt;/p&gt;
&lt;p&gt;Note(s)&lt;/p&gt;
&lt;p&gt;The following products are affected by the listed vulnerabilities:&lt;/p&gt;
&lt;p&gt;Series PFC100 (750-81xx/xxx-xxx)
Series PFC200 (750-82xx/xxx-xxx)&lt;/p&gt;
&lt;p&gt;The following products are affected by the vulnerability CVE-2019-5078&lt;/p&gt;
&lt;p&gt;750-852, 750-831/xxx-xxx, 750-881, 750-880/xxx-xxx, 750-889&lt;/p&gt;
&lt;p&gt;750-823, 750-832/xxx-xxx, 750-862, 750-890/xxx-xxx, 750-891&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The reported vulnerabilities allow a remote attacker to change the setting, delete the application, set the device to factory defaults, code execution and to cause a system crash or denial of service.&lt;/p&gt;
&lt;p&gt;Note(s)&lt;/p&gt;
&lt;p&gt;The following products are affected by the listed vulnerabilities:&lt;/p&gt;
&lt;p&gt;Series PFC100 (750-81xx/xxx-xxx)
Series PFC200 (750-82xx/xxx-xxx)&lt;/p&gt;
&lt;p&gt;The following products are affected by the vulnerability CVE-2019-5078&lt;/p&gt;
&lt;p&gt;750-852, 750-831/xxx-xxx, 750-881, 750-880/xxx-xxx, 750-889&lt;/p&gt;
&lt;p&gt;750-823, 750-832/xxx-xxx, 750-862, 750-890/xxx-xxx, 750-891&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-022</guid>
      <pubDate>Mon, 16 Dec 2019 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-004 — WAGO: e!Cockpit cleartext communication and hardcoded key</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-004</link>
      <description>&lt;p&gt;The communication between e!Cockpit and the programmable logic controller is not encrypted. The broken cryptographic algorithm allows an attacker to decode the password for the e!Cockpit communication and with this to manipulate the application.&lt;/p&gt;
&lt;p&gt;The password used by e!Cockpit for authentication against the PLC is encrypted with a hard-coded key. An attacker is able to decrypt the password by listening to the network traffic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The communication between e!Cockpit and the programmable logic controller is not encrypted. The broken cryptographic algorithm allows an attacker to decode the password for the e!Cockpit communication and with this to manipulate the application.&lt;/p&gt;
&lt;p&gt;The password used by e!Cockpit for authentication against the PLC is encrypted with a hard-coded key. An attacker is able to decrypt the password by listening to the network traffic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-004</guid>
      <pubDate>Mon, 09 Mar 2020 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-007 — WAGO: Web-Based Management Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-007</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for commissioning and update. The controller is an embedded device which has limited resources. The vulnerability described here takes advantage of this fact.With special crafted requests it is possible to have a denial of service of the WBM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for commissioning and update. The controller is an embedded device which has limited resources. The vulnerability described here takes advantage of this fact.With special crafted requests it is possible to have a denial of service of the WBM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-007</guid>
      <pubDate>Mon, 09 Mar 2020 09:10:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-008 — WAGO: Cloud Connectivity Multiple Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-008</link>
      <description>&lt;p&gt;The Cloud Connectivity of the WAGO PLCs is used to connect the device with the cloud services from different providers. It also supports maintenance functionality with the firmware update function from the WAGO cloud.
An attacker needs an authorized login with administrative privileges on the device in order to exploit the mentioned vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Cloud Connectivity of the WAGO PLCs is used to connect the device with the cloud services from different providers. It also supports maintenance functionality with the firmware update function from the WAGO cloud.
An attacker needs an authorized login with administrative privileges on the device in order to exploit the mentioned vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-008</guid>
      <pubDate>Mon, 09 Mar 2020 09:15:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-009 — WAGO: e!Cockpit Two Update Package Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-009</link>
      <description>&lt;p&gt;The firmware update package (WUP) is not signed entirely. The used password offers no additional security, it is just meant to protect from unintentional modifications of the WUP file. Thus only the integrity of the signed firmware part (rauc file) is protected against intended manipulation. An attacker could manipulate the WUP file in a way that additional files with potentially malicious content are added to the WUP file.
In case an authorized user that issues a firmware update could be tricked into installing this manipulated WUP file onto the device, the potentially malicious files would also be copied and installed on to the device and executed with elevated privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The firmware update package (WUP) is not signed entirely. The used password offers no additional security, it is just meant to protect from unintentional modifications of the WUP file. Thus only the integrity of the signed firmware part (rauc file) is protected against intended manipulation. An attacker could manipulate the WUP file in a way that additional files with potentially malicious content are added to the WUP file.
In case an authorized user that issues a firmware update could be tricked into installing this manipulated WUP file onto the device, the potentially malicious files would also be copied and installed on to the device and executed with elevated privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-009</guid>
      <pubDate>Mon, 09 Mar 2020 09:18:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-010 — WAGO: Cloud Connectivity Remote Code Execution Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-010</link>
      <description>&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.
The weakness allows an attacker which has admin privileges on the device to redirect to his own Azure cloud account and install malicious software with the firmware update functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.
The weakness allows an attacker which has admin privileges on the device to redirect to his own Azure cloud account and install malicious software with the firmware update functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-010</guid>
      <pubDate>Mon, 09 Mar 2020 09:25:00 +0000</pubDate>
    </item>
  </channel>
</rss>
