WAGO: Authentication Vulnerability in Web-Based Management
Vulnerability Description
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34578
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maxim Rupp (https://rupp.it) reported this vulnerability to WAGO. CERT@VDE coordinated.
More from WAGO
View All →Affected Vendor
WAGO
View all reports →