Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WAGO | 0765-110x/0100-0000 | >= 1.0.0.0, < 1.2.1.100CNA affecteddefault unaffected | |
| WAGO | 0765-120x/0100-0000 | >= 1.0.0.0, < 1.2.7.100CNA affecteddefault unaffected | |
| WAGO | 0765-150x/0100-0000 | >= 1.0.0.0, < 1.2.7.103CNA affecteddefault unaffected | |
| WAGO | 0765-2101/0100-0000 | >= 1.0.0.0, < 1.2.1.102CNA affecteddefault unaffected | |
| WAGO | 0765-2102/0100-0000 | >= 1.0.0.0, < 1.2.5.101CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.