Vulnerabilidades en WAGO

98 resultados
Análisis Vexday

Com 64 CVEs catalogadas, o portfólio de vulnerabilidades da WAGO apresenta 20 entradas de severidade crítica — um volume que exige atenção contínua em ambientes de tecnologia operacional. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores de ameaça no momento, o que oferece uma janela para priorização proativa de remediações. O ponto de maior preocupação imediata é CVE-2023-1698, com escore EPSS de 0,8191, indicando alta probabilidade estatística de exploração — essa falha merece tratamento prioritário independentemente da ausência de registro formal no KEV. O tipo de fraqueza mais recorrente, CWE-306 (ausência de autenticação para função crítica), é especialmente relevante em contextos industriais onde o acesso não autenticado a funções de controle pode ter consequências físicas diretas.

CVE-2024-41971HIGHWAGO: Arbitrary File Overwrite in Multiple DevicesEPSS 0.6%CVE-2021-20994HIGHWAGO: Managed Switches: Reflected Cross-site ScriptingEPSS 0.6%CVE-2022-3738MEDIUMWAGO: Missing authentication for config export functionality in multiple productsEPSS 0.6%CVE-2024-41972MEDIUMWAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple DevicesEPSS 0.6%CVE-2026-22904CRITICALStack Overflow via Oversized Cookie Fields in lighttpdEPSS 0.6%CVE-2022-22511MEDIUMWAGO PLCs WBM vulnerable to reflected XSSEPSS 0.6%CVE-2022-50926HIGHWAGO 750-8212 PFC200 G2 2ETH RS Privilege EscalationEPSS 0.6%CVE-2021-20995MEDIUMWAGO: Managed Switches: Storage of user credentials in a cookieEPSS 0.5%CVE-2019-5182An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2019-5176An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2018-25108HIGHWAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionEPSS 0.5%CVE-2024-41969HIGHWAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesEPSS 0.5%CVE-2025-41715CRITICALMissing Authentication for Database Access in Web ApplicationEPSS 0.5%CVE-2023-4089LOWWAGO: Multiple products vulnerable to local file inclusionEPSS 0.5%CVE-2019-5177An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2025-25265MEDIUMUnauthenticated File Read via Web InterfaceEPSS 0.5%CVE-2025-25264MEDIUMOverly Permissive CORS Policy in WAGO Device ManagerEPSS 0.4%CVE-2025-41730CRITICALStack-based buffer overflow via unsafe sscanf in check_account()EPSS 0.4%CVE-2025-41732CRITICALStack-based buffer overflow via unsafe sscanf in check_cookie()EPSS 0.4%CVE-2024-41967HIGHWAGO: Boot Mode Manipulation in Multiple DevicesEPSS 0.4%