CVE-2018-16210

WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
wago750-362_firmware
𝑥
< 05
wago750-363_firmware
𝑥
< 05
wago750-823_firmware
𝑥
< 05
wago750-832_firmware
𝑥
< 05
wago750-862_firmware
𝑥
< 05
wago750-891_firmware
𝑥
< 05
wago750-890_firmware
𝑥
< 05
wago750-352_firmware
𝑥
< 14
wago750-831_firmware
𝑥
< 14
wago750-852_firmware
𝑥
< 14
wago750-880_firmware
𝑥
< 14
wago750-881_firmware
𝑥
< 14
wago750-889_firmware
𝑥
< 14
wagowago_750-881_ethernet_controller_devices_firmware
01.08.01\(10\)
wagowago_750-881_ethernet_controller_devices_firmware
01.09.18\(13\)
𝑥
= Vulnerable software versions