CVE-2021-21001

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
wago750-8202_firmware
𝑥
< 03.06.19_\(18\)
wago750-8203_firmware
𝑥
< 03.06.19_\(18\)
wago750-8204_firmware
𝑥
< 03.06.19_\(18\)
wago750-8206_firmware
𝑥
< 03.06.19_\(18\)
wago750-8207_firmware
𝑥
< 03.06.19_\(18\)
wago750-8208_firmware
𝑥
< 03.06.19_\(18\)
wago750-8210_firmware
𝑥
< 03.06.19_\(18\)
wago750-8211_firmware
𝑥
< 03.06.19_\(18\)
wago750-8212_firmware
𝑥
< 03.06.19_\(18\)
wago750-8213_firmware
𝑥
< 03.06.19_\(18\)
wago750-8214_firmware
𝑥
< 03.06.19_\(18\)
wago750-8216_firmware
𝑥
< 03.06.19_\(18\)
wago750-8217_firmware
𝑥
< 03.06.19_\(18\)
𝑥
= Vulnerable software versions