ZeroHour

CVE-2021-34566

CVSS 3.1
9.1 critical
EPSS
1%p64
Published
()
Modified
Description

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

Vendors
wago
Products
750-8100 firmware, 750-8101 firmware, 750-8101\/025-000 firmware, 750-8102 firmware, 750-8102\/025-000 firmware, 750-8202 firmware, 750-8202\/000-011 firmware, 750-8202\/000-012 firmware, 750-8202\/000-022 firmware, 750-8202\/025-000 firmware, 750-8202\/025-001 firmware, 750-8202\/025-002 firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news