CVE-2018-8836
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
Published:Apr 3, 2018
Last Modified:Nov 21, 2024
EPS:Apr 3, 2018
EPSS Score:0.03324
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Wago
Product
750-829
Wago
750-829
Vendor
Wago
Product
750-829 Firmware
Wago
750-829 Firmware
Vendor
Wago
Product
750-831
Wago
750-831
Vendor
Wago
Product
750-831 Firmware
Wago
750-831 Firmware
Vendor
Wago
Product
750-852
Wago
750-852
Vendor
Wago
Product
750-852 Firmware
Wago
750-852 Firmware
Vendor
Wago
Product
750-880
Wago
750-880
Vendor
Wago
Product
750-880 Firmware
Wago
750-880 Firmware
Vendor
Wago
Product
750-881
Wago
750-881
Vendor
Wago
Product
750-881 Firmware
Wago
750-881 Firmware
Vendor
Wago
Product
750-882
Wago
750-882
Vendor
Wago
Product
750-882 Firmware
Wago
750-882 Firmware
Vendor
Wago
Product
750-885
Wago
750-885
Vendor
Wago
Product
750-885 Firmware
Wago
750-885 Firmware
Vendor
Wago
Product
750-889
Wago
750-889
Vendor
Wago
Product
750-889 Firmware
Wago
750-889 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
