CVE-2018-8836
03.04.2018, 13:29
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.Enginsight
Vendor | Product | Version |
---|---|---|
wago | 750-880_firmware | 𝑥 ≤ 10 |
wago | 750-881_firmware | 𝑥 ≤ 10 |
wago | 750-852_firmware | 𝑥 ≤ 10 |
wago | 750-882_firmware | 𝑥 ≤ 10 |
wago | 750-885_firmware | 𝑥 ≤ 10 |
wago | 750-831_firmware | 𝑥 ≤ 10 |
wago | 750-889_firmware | 𝑥 ≤ 10 |
wago | 750-829_firmware | 𝑥 ≤ 10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References