Lucene search

K
cve[email protected]CVE-2021-34567
HistoryNov 09, 2022 - 4:15 p.m.

CVE-2021-34567

2022-11-0916:15:11
CWE-125
web.nvd.nist.gov
33
6
cve-2021-34567
wago
i/o-check service
os command execution
denial of service
nvd
out-of-bounds read

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.3%

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.

Affected configurations

NVD
Node
wago750-8100_firmwareRange<18
OR
wago750-8100_firmwareMatch18-
OR
wago750-8100_firmwareMatch18patch_1
OR
wago750-8100_firmwareMatch18patch_2
AND
wago750-8100Match-
Node
wago750-8101_firmwareRange<18
OR
wago750-8101_firmwareMatch18-
OR
wago750-8101_firmwareMatch18patch_1
OR
wago750-8101_firmwareMatch18patch_2
AND
wago750-8101Match-
Node
wago750-8101\/025-000_firmwareRange<18
OR
wago750-8101\/025-000_firmwareMatch18-
OR
wago750-8101\/025-000_firmwareMatch18patch_1
OR
wago750-8101\/025-000_firmwareMatch18patch_2
AND
wago750-8101\/025-000Match-
Node
wago750-8102_firmwareRange<18
OR
wago750-8102_firmwareMatch18-
OR
wago750-8102_firmwareMatch18patch_1
OR
wago750-8102_firmwareMatch18patch_2
AND
wago750-8102Match-
Node
wago750-8102\/025-000_firmwareRange<18
OR
wago750-8102\/025-000_firmwareMatch18-
OR
wago750-8102\/025-000_firmwareMatch18patch_1
OR
wago750-8102\/025-000_firmwareMatch18patch_2
AND
wago750-8102\/025-000Match-
Node
wago750-8202_firmwareRange<18
OR
wago750-8202_firmwareMatch18-
OR
wago750-8202_firmwareMatch18patch_1
OR
wago750-8202_firmwareMatch18patch_2
AND
wago750-8202Match-
Node
wago750-8202\/000-011_firmwareRange<18
OR
wago750-8202\/000-011_firmwareMatch18-
OR
wago750-8202\/000-011_firmwareMatch18patch_1
OR
wago750-8202\/000-011_firmwareMatch18patch_2
AND
wago750-8202\/000-011Match-
Node
wago750-8202\/000-012_firmwareRange<18
OR
wago750-8202\/000-012_firmwareMatch18-
OR
wago750-8202\/000-012_firmwareMatch18patch_1
OR
wago750-8202\/000-012_firmwareMatch18patch_2
AND
wago750-8202\/000-012Match-
Node
wago750-8202\/000-022_firmwareRange<18
OR
wago750-8202\/000-022_firmwareMatch18-
OR
wago750-8202\/000-022_firmwareMatch18patch_1
OR
wago750-8202\/000-022_firmwareMatch18patch_2
AND
wago750-8202\/000-022Match-
Node
wago750-8202\/025-000_firmwareRange<18
OR
wago750-8202\/025-000_firmwareMatch18-
OR
wago750-8202\/025-000_firmwareMatch18patch_1
OR
wago750-8202\/025-000_firmwareMatch18patch_2
AND
wago750-8202\/025-000Match-
Node
wago750-8202\/025-001_firmwareRange<18
OR
wago750-8202\/025-001_firmwareMatch18-
OR
wago750-8202\/025-001_firmwareMatch18patch_1
OR
wago750-8202\/025-001_firmwareMatch18patch_2
AND
wago750-8202\/025-001Match-
Node
wago750-8202\/025-002_firmwareRange<18
OR
wago750-8202\/025-002_firmwareMatch18-
OR
wago750-8202\/025-002_firmwareMatch18patch_1
OR
wago750-8202\/025-002_firmwareMatch18patch_2
AND
wago750-8202\/025-002Match-
Node
wago750-8202\/040-000_firmwareRange<18
OR
wago750-8202\/040-000_firmwareMatch18-
OR
wago750-8202\/040-000_firmwareMatch18patch_1
OR
wago750-8202\/040-000_firmwareMatch18patch_2
AND
wago750-8202\/040-000Match-
Node
wago750-8202\/040-001_firmwareRange<18
OR
wago750-8202\/040-001_firmwareMatch18-
OR
wago750-8202\/040-001_firmwareMatch18patch_1
OR
wago750-8202\/040-001_firmwareMatch18patch_2
AND
wago750-8202\/040-001Match-
Node
wago752-8303\/8000-002_firmwareRange<18
OR
wago752-8303\/8000-002_firmwareMatch18-
OR
wago752-8303\/8000-002_firmwareMatch18patch_1
OR
wago752-8303\/8000-002_firmwareMatch18patch_2
AND
wago752-8303\/8000-002Match-
Node
wago762-4101_firmwareRange<18
OR
wago762-4101_firmwareMatch18-
OR
wago762-4101_firmwareMatch18patch_1
OR
wago762-4101_firmwareMatch18patch_2
AND
wago762-4101Match-
Node
wago762-4102_firmwareRange<18
OR
wago762-4102_firmwareMatch18-
OR
wago762-4102_firmwareMatch18patch_1
OR
wago762-4102_firmwareMatch18patch_2
AND
wago762-4102Match-
Node
wago762-4103_firmwareRange<18
OR
wago762-4103_firmwareMatch18-
OR
wago762-4103_firmwareMatch18patch_1
OR
wago762-4103_firmwareMatch18patch_2
AND
wago762-4103Match-
Node
wago762-4104_firmwareRange<18
OR
wago762-4104_firmwareMatch18-
OR
wago762-4104_firmwareMatch18patch_1
OR
wago762-4104_firmwareMatch18patch_2
AND
wago762-4104Match-
Node
wago762-4201\/8000-001_firmwareRange<18
OR
wago762-4201\/8000-001_firmwareMatch18-
OR
wago762-4201\/8000-001_firmwareMatch18patch_1
OR
wago762-4201\/8000-001_firmwareMatch18patch_2
AND
wago762-4201\/8000-001Match-
Node
wago762-4202\/8000-001_firmwareRange<18
OR
wago762-4202\/8000-001_firmwareMatch18-
OR
wago762-4202\/8000-001_firmwareMatch18patch_1
OR
wago762-4202\/8000-001_firmwareMatch18patch_2
AND
wago762-4202\/8000-001Match-
Node
wago762-4203\/8000-001Match-
AND
wago762-4203\/8000-001_firmwareRange<18
OR
wago762-4203\/8000-001_firmwareMatch18-
OR
wago762-4203\/8000-001_firmwareMatch18patch_1
OR
wago762-4203\/8000-001_firmwareMatch18patch_2
Node
wago762-4204\/8000-001Match-
AND
wago762-4204\/8000-001_firmwareRange<18
OR
wago762-4204\/8000-001_firmwareMatch18-
OR
wago762-4204\/8000-001_firmwareMatch18patch_1
OR
wago762-4204\/8000-001_firmwareMatch18patch_2
Node
wago762-4205\/8000-001Match-
AND
wago762-4205\/8000-001_firmwareRange<18
OR
wago762-4205\/8000-001_firmwareMatch18-
OR
wago762-4205\/8000-001_firmwareMatch18patch_1
OR
wago762-4205\/8000-001_firmwareMatch18patch_2
Node
wago762-4205\/8000-002Match-
AND
wago762-4205\/8000-002_firmwareRange<18
OR
wago762-4205\/8000-002_firmwareMatch18-
OR
wago762-4205\/8000-002_firmwareMatch18patch_1
OR
wago762-4205\/8000-002_firmwareMatch18patch_2
Node
wago762-4206\/8000-001Match-
AND
wago762-4206\/8000-001_firmwareRange<18
OR
wago762-4206\/8000-001_firmwareMatch18-
OR
wago762-4206\/8000-001_firmwareMatch18patch_1
OR
wago762-4206\/8000-001_firmwareMatch18patch_2
Node
wago762-4206\/8000-002Match-
AND
wago762-4206\/8000-002_firmwareRange<18
OR
wago762-4206\/8000-002_firmwareMatch18-
OR
wago762-4206\/8000-002_firmwareMatch18patch_1
OR
wago762-4206\/8000-002_firmwareMatch18patch_2
Node
wago762-4301\/8000-002Match-
AND
wago762-4301\/8000-002_firmwareRange<18
OR
wago762-4301\/8000-002_firmwareMatch18-
OR
wago762-4301\/8000-002_firmwareMatch18patch_1
OR
wago762-4301\/8000-002_firmwareMatch18patch_2
Node
wago762-4302\/8000-002Match-
AND
wago762-4302\/8000-002_firmwareRange<18
OR
wago762-4302\/8000-002_firmwareMatch18-
OR
wago762-4302\/8000-002_firmwareMatch18patch_1
OR
wago762-4302\/8000-002_firmwareMatch18patch_2
Node
wago762-4303\/8000-002_firmwareRange<18
OR
wago762-4303\/8000-002_firmwareMatch18-
OR
wago762-4303\/8000-002_firmwareMatch18patch_1
OR
wago762-4303\/8000-002_firmwareMatch18patch_2
AND
wago762-4303\/8000-002Match-
Node
wago762-4304\/8000-002_firmwareRange<18
OR
wago762-4304\/8000-002_firmwareMatch18-
OR
wago762-4304\/8000-002_firmwareMatch18patch_1
OR
wago762-4304\/8000-002_firmwareMatch18patch_2
AND
wago762-4304\/8000-002Match-
Node
wago762-4305\/8000-002_firmwareRange<18
OR
wago762-4305\/8000-002_firmwareMatch18-
OR
wago762-4305\/8000-002_firmwareMatch18patch_1
OR
wago762-4305\/8000-002_firmwareMatch18patch_2
AND
wago762-4305\/8000-002Match-
Node
wago762-4306\/8000-002_firmwareRange<18
OR
wago762-4306\/8000-002_firmwareMatch18-
OR
wago762-4306\/8000-002_firmwareMatch18patch_1
OR
wago762-4306\/8000-002_firmwareMatch18patch_2
AND
wago762-4306\/8000-002Match-
Node
wago762-5203\/8000-001_firmwareRange<18
OR
wago762-5203\/8000-001_firmwareMatch18-
OR
wago762-5203\/8000-001_firmwareMatch18patch_1
OR
wago762-5203\/8000-001_firmwareMatch18patch_2
AND
wago762-5203\/8000-001Match-
Node
wago762-5204\/8000-001_firmwareRange<18
OR
wago762-5204\/8000-001_firmwareMatch18-
OR
wago762-5204\/8000-001_firmwareMatch18patch_1
OR
wago762-5204\/8000-001_firmwareMatch18patch_2
AND
wago762-5204\/8000-001Match-
Node
wago762-5205\/8000-001_firmwareRange<18
OR
wago762-5205\/8000-001_firmwareMatch18-
OR
wago762-5205\/8000-001_firmwareMatch18patch_1
OR
wago762-5205\/8000-001_firmwareMatch18patch_2
AND
wago762-5205\/8000-001Match-
Node
wago762-5206\/8000-001_firmwareRange<18
OR
wago762-5206\/8000-001_firmwareMatch18-
OR
wago762-5206\/8000-001_firmwareMatch18patch_1
OR
wago762-5206\/8000-001_firmwareMatch18patch_2
AND
wago762-5206\/8000-001Match-
Node
wago762-5303\/8000-002_firmwareRange<18
OR
wago762-5303\/8000-002_firmwareMatch18-
OR
wago762-5303\/8000-002_firmwareMatch18patch_1
OR
wago762-5303\/8000-002_firmwareMatch18patch_2
AND
wago762-5303\/8000-002Match-
Node
wago762-5304\/8000-002_firmwareRange<18
OR
wago762-5304\/8000-002_firmwareMatch18-
OR
wago762-5304\/8000-002_firmwareMatch18patch_1
OR
wago762-5304\/8000-002_firmwareMatch18patch_2
AND
wago762-5304\/8000-002Match-
Node
wago762-5305\/8000-002_firmwareRange<18
OR
wago762-5305\/8000-002_firmwareMatch18-
OR
wago762-5305\/8000-002_firmwareMatch18patch_1
OR
wago762-5305\/8000-002_firmwareMatch18patch_2
AND
wago762-5305\/8000-002Match-
Node
wago762-5306\/8000-002_firmwareRange<18
OR
wago762-5306\/8000-002_firmwareMatch18-
OR
wago762-5306\/8000-002_firmwareMatch18patch_1
OR
wago762-5306\/8000-002_firmwareMatch18patch_2
AND
wago762-5306\/8000-002Match-
Node
wago762-6201\/8000-001_firmwareRange<18
OR
wago762-6201\/8000-001_firmwareMatch18-
OR
wago762-6201\/8000-001_firmwareMatch18patch_1
OR
wago762-6201\/8000-001_firmwareMatch18patch_2
AND
wago762-6201\/8000-001Match-
Node
wago762-6202\/8000-001_firmwareRange<18
OR
wago762-6202\/8000-001_firmwareMatch18-
OR
wago762-6202\/8000-001_firmwareMatch18patch_1
OR
wago762-6202\/8000-001_firmwareMatch18patch_2
AND
wago762-6202\/8000-001Match-
Node
wago762-6203\/8000-001_firmwareRange<18
OR
wago762-6203\/8000-001_firmwareMatch18-
OR
wago762-6203\/8000-001_firmwareMatch18patch_1
OR
wago762-6203\/8000-001_firmwareMatch18patch_2
AND
wago762-6203\/8000-001Match-
Node
wago762-6204\/8000-001_firmwareRange<18
OR
wago762-6204\/8000-001_firmwareMatch18-
OR
wago762-6204\/8000-001_firmwareMatch18patch_1
OR
wago762-6204\/8000-001_firmwareMatch18patch_2
AND
wago762-6204\/8000-001Match-
Node
wago762-6301\/8000-002_firmwareRange<18
OR
wago762-6301\/8000-002_firmwareMatch18-
OR
wago762-6301\/8000-002_firmwareMatch18patch_1
OR
wago762-6301\/8000-002_firmwareMatch18patch_2
AND
wago762-6301\/8000-002Match-
Node
wago762-6302\/8000-002_firmwareRange<18
OR
wago762-6302\/8000-002_firmwareMatch18-
OR
wago762-6302\/8000-002_firmwareMatch18patch_1
OR
wago762-6302\/8000-002_firmwareMatch18patch_2
AND
wago762-6302\/8000-002Match-
Node
wago762-6303\/8000-002_firmwareRange<18
OR
wago762-6303\/8000-002_firmwareMatch18-
OR
wago762-6303\/8000-002_firmwareMatch18patch_1
OR
wago762-6303\/8000-002_firmwareMatch18patch_2
AND
wago762-6303\/8000-002Match-
Node
wago762-6304\/8000-002_firmwareRange<18
OR
wago762-6304\/8000-002_firmwareMatch18-
OR
wago762-6304\/8000-002_firmwareMatch18patch_1
OR
wago762-6304\/8000-002_firmwareMatch18patch_2
AND
wago762-6304\/8000-002Match-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "750-81xx/xxx-xxxFW",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "750-82xx/xxx-xxx",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "752-8303/8000-0002",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "762-4xxx",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "762-5xxx",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "762-6xxx",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW18 Patch 2",
        "status": "affected",
        "version": "FW1",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.3%