Lucene search

K
cvelistCERTVDECVELIST:CVE-2015-10123
HistoryMar 13, 2024 - 8:31 a.m.

CVE-2015-10123 Wago: Buffer Copy without Checking Size of Input in wbm of multiple products

2024-03-1308:31:55
CWE-120
CERTVDE
www.cve.org
cve-2015-10123
wago
buffer copy
remote attacker
crafted packets
authenticated user
web-based management
full access

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%

An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Controller BACnet/IP",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Controller BACnet MS/TP",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Ethernet Controller 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Ethernet Controller 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Fieldbus Coupler Ethernet 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.3%

Related for CVELIST:CVE-2015-10123