Vulnerabilidades en WAGO

98 resultados
Análisis Vexday

Com 64 CVEs catalogadas, o portfólio de vulnerabilidades da WAGO apresenta 20 entradas de severidade crítica — um volume que exige atenção contínua em ambientes de tecnologia operacional. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores de ameaça no momento, o que oferece uma janela para priorização proativa de remediações. O ponto de maior preocupação imediata é CVE-2023-1698, com escore EPSS de 0,8191, indicando alta probabilidade estatística de exploração — essa falha merece tratamento prioritário independentemente da ausência de registro formal no KEV. O tipo de fraqueza mais recorrente, CWE-306 (ausência de autenticação para função crítica), é especialmente relevante em contextos industriais onde o acesso não autenticado a funções de controle pode ter consequências físicas diretas.

CVE-2021-34569CRITICALWAGO I/O-Check Service prone to Out-of-bounds WriteEPSS 0.9%CVE-2023-1620MEDIUMWAGO: DoS in multiple products in multiple versions using CodesysEPSS 0.9%CVE-2021-34567HIGHWAGO I/O-Check Service prone to Out-of-bounds ReadEPSS 0.8%CVE-2019-5181An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.8%CVE-2019-5166An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02EPSS 0.8%CVE-2021-20993MEDIUMWAGO: Managed Switches: Exposure of sensitive information through directory listingEPSS 0.8%CVE-2023-1619MEDIUMWAGO: DoS in multiple versions of multiple productsEPSS 0.8%CVE-2026-4769CRITICALUnauthenticated Access to Internal Diagnostic InterfaceEPSS 0.8%CVE-2021-20996MEDIUMWAGO: Managed Switches: Unsecure Cookie settingsEPSS 0.8%CVE-2022-45138CRITICALWAGO: Missing Authentication for Critical FunctionEPSS 0.7%CVE-2024-1490HIGHWago: Vulnerability in WBM through Open VPNEPSS 0.7%CVE-2022-3281HIGHWAGO: multiple products - Loss of MAC-Address-Filtering after rebootEPSS 0.7%CVE-2026-3587CRITICALHidden CLI Function Allows Root AccessEPSS 0.7%CVE-2026-22903CRITICALStack Overflow via SESSIONID Cookie in lighttpdEPSS 0.7%CVE-2019-5180An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.7%CVE-2019-5178An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.7%CVE-2019-5179An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.7%CVE-2015-10123HIGHWago: Buffer Copy without Checking Size of Input in wbm of multiple productsEPSS 0.6%CVE-2024-41973HIGHWAGO: Remote Arbitrary File Write with Root Privileges in multiple DevicesEPSS 0.6%CVE-2026-22905HIGHAuthentication Bypass via URI TraversalEPSS 0.6%