<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_wagogmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 02:36:56 +0000</lastBuildDate>
    <item>
      <title>VDE-2019-013 — WAGO: Multiple Vulnerabilities in industrial managed switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-013</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO 852-303, 852-1305 and 852-1505 industrial managed ethernet switches.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO 852-303, 852-1305 and 852-1505 industrial managed ethernet switches.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-013</guid>
      <pubDate>Wed, 12 Jun 2019 10:25:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-022 — WAGO: Multiple Vulnerabilities in I/O-Check Service in Multiple Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-022</link>
      <description>&lt;p&gt;The reported vulnerabilities allow a remote attacker to change the setting, delete the application, set the device to factory defaults, code execution and to cause a system crash or denial of service.&lt;/p&gt;
&lt;p&gt;Note(s)&lt;/p&gt;
&lt;p&gt;The following products are affected by the listed vulnerabilities:&lt;/p&gt;
&lt;p&gt;Series PFC100 (750-81xx/xxx-xxx)
Series PFC200 (750-82xx/xxx-xxx)&lt;/p&gt;
&lt;p&gt;The following products are affected by the vulnerability CVE-2019-5078&lt;/p&gt;
&lt;p&gt;750-852, 750-831/xxx-xxx, 750-881, 750-880/xxx-xxx, 750-889&lt;/p&gt;
&lt;p&gt;750-823, 750-832/xxx-xxx, 750-862, 750-890/xxx-xxx, 750-891&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The reported vulnerabilities allow a remote attacker to change the setting, delete the application, set the device to factory defaults, code execution and to cause a system crash or denial of service.&lt;/p&gt;
&lt;p&gt;Note(s)&lt;/p&gt;
&lt;p&gt;The following products are affected by the listed vulnerabilities:&lt;/p&gt;
&lt;p&gt;Series PFC100 (750-81xx/xxx-xxx)
Series PFC200 (750-82xx/xxx-xxx)&lt;/p&gt;
&lt;p&gt;The following products are affected by the vulnerability CVE-2019-5078&lt;/p&gt;
&lt;p&gt;750-852, 750-831/xxx-xxx, 750-881, 750-880/xxx-xxx, 750-889&lt;/p&gt;
&lt;p&gt;750-823, 750-832/xxx-xxx, 750-862, 750-890/xxx-xxx, 750-891&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-022</guid>
      <pubDate>Mon, 16 Dec 2019 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-007 — WAGO: Web-Based Management Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-007</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for commissioning and update. The controller is an embedded device which has limited resources. The vulnerability described here takes advantage of this fact.With special crafted requests it is possible to have a denial of service of the WBM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for commissioning and update. The controller is an embedded device which has limited resources. The vulnerability described here takes advantage of this fact.With special crafted requests it is possible to have a denial of service of the WBM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-007</guid>
      <pubDate>Mon, 09 Mar 2020 09:10:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-010 — WAGO: Cloud Connectivity Remote Code Execution Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-010</link>
      <description>&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.
The weakness allows an attacker which has admin privileges on the device to redirect to his own Azure cloud account and install malicious software with the firmware update functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.
The weakness allows an attacker which has admin privileges on the device to redirect to his own Azure cloud account and install malicious software with the firmware update functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-010</guid>
      <pubDate>Mon, 09 Mar 2020 09:25:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-015 — WAGO: Web Based Management - Code Execution Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-015</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.&lt;/p&gt;
&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.&lt;/p&gt;
&lt;p&gt;An authenticated attacker who has access to the Web Based Management (WBM) could use the software upload functionality to install software package with root privileges. This fact could be potentially used to manipulate the device or to get control of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.&lt;/p&gt;
&lt;p&gt;An attacker needs an authorized login with administrative privileges on the device in order to exploit the herein mentioned vulnerability.&lt;/p&gt;
&lt;p&gt;An authenticated attacker who has access to the Web Based Management (WBM) could use the software upload functionality to install software package with root privileges. This fact could be potentially used to manipulate the device or to get control of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-015</guid>
      <pubDate>Wed, 10 Jun 2020 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-048 — M&amp;M Software (WAGO): Deserialisation of untrusted data in fdtContainer</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-048</link>
      <description>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-048</guid>
      <pubDate>Thu, 14 Jan 2021 14:57:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-050 — WAGO: Multiple devices affected by Vulnerabilities in NUCLEUS TCP Stack.</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-050</link>
      <description>&lt;p&gt;Multiple vulnerabilities were reported in the Nucleus Real-Time Operating System (RTOS). The Nucleus RTOS is an essential component in several WAGO PLCs and fieldbus coupler. WAGO uses older Versions of the Nucleus RTOS also in legacy products.
For additional information please consult the official Siemens advisory:
• Advisory SSA-044112&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities were reported in the Nucleus Real-Time Operating System (RTOS). The Nucleus RTOS is an essential component in several WAGO PLCs and fieldbus coupler. WAGO uses older Versions of the Nucleus RTOS also in legacy products.
For additional information please consult the official Siemens advisory:
• Advisory SSA-044112&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-050</guid>
      <pubDate>Tue, 16 Nov 2021 11:02:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-004 — WAGO: Web-Based Management Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-004</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-004</guid>
      <pubDate>Wed, 09 Mar 2022 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-031 — WAGO: Multiple Products Series affected by multiple CODESYS vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-031</link>
      <description>&lt;p&gt;Multiple WAGO product families are prone to multiple vulnerabilities affecting CODESYS control runtime system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO product families are prone to multiple vulnerabilities affecting CODESYS control runtime system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-031</guid>
      <pubDate>Wed, 17 Aug 2022 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-035 — WAGO: Multiple product series affected by multiple CODESYS vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-035</link>
      <description>&lt;p&gt;Multiple WAGO product families are prone to multiple vulnerabilities affecting CODESYS control runtime system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO product families are prone to multiple vulnerabilities affecting CODESYS control runtime system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-035</guid>
      <pubDate>Wed, 17 Aug 2022 08:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
