Vulnerabilidades em WAGO

98 resultados
Análise Vexday

Com 64 CVEs catalogadas, o portfólio de vulnerabilidades da WAGO apresenta 20 entradas de severidade crítica — um volume que exige atenção contínua em ambientes de tecnologia operacional. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores de ameaça no momento, o que oferece uma janela para priorização proativa de remediações. O ponto de maior preocupação imediata é CVE-2023-1698, com escore EPSS de 0,8191, indicando alta probabilidade estatística de exploração — essa falha merece tratamento prioritário independentemente da ausência de registro formal no KEV. O tipo de fraqueza mais recorrente, CWE-306 (ausência de autenticação para função crítica), é especialmente relevante em contextos industriais onde o acesso não autenticado a funções de controle pode ter consequências físicas diretas.

CVE-2018-25090MEDIUMWago: Improper Neutralization of Input During Web Page Generation in multiple devicesEPSS 0.4%CVE-2025-41716MEDIUMUnauthenticated User Enumeration via Missing AuthenticationEPSS 0.4%CVE-2025-0101MEDIUMWAGO: Year 2038 problemEPSS 0.4%CVE-2022-45137MEDIUMWAGO: Reflective Cross-Site ScriptingEPSS 0.4%CVE-2025-41713MEDIUMWAGO: Vulnerability in hardware switch circuitEPSS 0.4%CVE-2025-41672CRITICALWAGO: Vulnerability in WAGO Device SphereEPSS 0.4%CVE-2024-41974HIGHWAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple DevicesEPSS 0.4%CVE-2024-41970MEDIUMWAGO: Unauthorized Diagnostic Data Exposure in Multiple DevicesEPSS 0.3%CVE-2024-41968MEDIUMWAGO: Docker Settings Manipulation in Multiple DevicesEPSS 0.3%CVE-2019-5106A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with accEPSS 0.3%CVE-2026-22906CRITICALHardcoded Key Allows Credential DisclosureEPSS 0.3%CVE-2023-5872MEDIUMWago: Vulnerability in Smart Designer Web-ApplicationEPSS 0.3%CVE-2026-2328HIGHBackend Access Due to Insufficient Input ValidationEPSS 0.3%CVE-2024-12650MEDIUMWago: Vulnerability in libwagosnmpEPSS 0.3%CVE-2025-1235MEDIUMWAGO: Switches affected by year 2k38 problemEPSS 0.3%CVE-2022-45139MEDIUMWAGO: Origin validation error through CORS misconfigurationEPSS 0.3%CVE-2025-41664HIGHImproper Permission Handling Enables Unauthorized Access to Firmware and CertificatesEPSS 0.2%CVE-2023-3379MEDIUMWAGO: Improper Privilege Management in web-based managementEPSS 0.2%