VendorsWAGO750-8206any version
Vulnerabilities

WAGO 750-8206 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2018-5459
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Published 2018-02-13 · Modified
9.8EPSS 0.027
CVE-2021-30190
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
Published 2021-05-25 · Analyzed
9.8EPSS 0.014
CVE-2021-30188
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
Published 2021-05-25 · Analyzed
9.8EPSS 0.013
CVE-2021-30189
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
Published 2021-05-25 · Analyzed
9.8EPSS 0.013
CVE-2021-30193
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
Published 2021-05-25 · Analyzed
9.8EPSS 0.012
CVE-2021-30192
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
Published 2021-05-25 · Analyzed
9.8EPSS 0.012
CVE-2021-30194
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
Published 2021-05-25 · Analyzed
9.1EPSS 0.012
CVE-2021-21001
WAGO: PFC200 Access to files outside the home directory
Published 2021-05-24 · Analyzed
9.1EPSS 0.011
CVE-2021-34584
CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS)
Published 2021-10-26 · Analyzed
9.1EPSS 0.011
CVE-2021-34595
CODESYS V2 runtime: out-of-bounds read or write access may result in denial-of-service
Published 2021-10-26 · Analyzed
8.1EPSS 0.009
CVE-2020-12069
CODESYS V3 prone to Inadequate Password Hashing
Published 2022-12-26 · Analyzed
7.8EPSS 0.002
CVE-2021-34586
CODESYS V2 web server: crafted requests could trigger a null pointer dereference (DoS)
Published 2021-10-26 · Analyzed
7.5EPSS 0.141
CVE-2021-34583
CODESYS V2 web server: crafted requests could trigger a heap-based buffer overflow (DoS)
Published 2021-10-26 · Analyzed
7.5EPSS 0.084
CVE-2021-30186
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Published 2021-05-25 · Analyzed
7.5EPSS 0.074
CVE-2021-30195
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Published 2021-05-25 · Analyzed
7.5EPSS 0.072
CVE-2021-34593
CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
Published 2021-10-26 · Analyzed
7.5EPSS 0.027
CVE-2021-21000
WAGO: PFC200 Denial of Service due to the number of connections to the runtime
Published 2021-05-24 · Analyzed
7.5EPSS 0.010
CVE-2021-30191
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
Published 2021-05-25 · Analyzed
7.5EPSS 0.010
CVE-2021-34585
CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)
Published 2021-10-26 · Analyzed
7.5EPSS 0.009
CVE-2022-3281
WAGO: multiple products - Loss of MAC-Address-Filtering after reboot
Published 2022-10-17 · Modified
7.5EPSS 0.007
CVE-2021-34596
CODESYS V2 runtime: Access of Uninitialized Pointer may result in denial-of-service
Published 2021-10-26 · Analyzed
6.5EPSS 0.009
CVE-2021-30187
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
Published 2021-05-25 · Analyzed
5.3EPSS 0.003
CVE-2023-1620
WAGO: DoS in multiple products in multiple versions using Codesys
Published 2023-06-26 · Modified
4.9EPSS 0.009
CVE-2023-1619
WAGO: DoS in multiple versions of multiple products
Published 2023-06-26 · Modified
4.9EPSS 0.008