Page 19 of 96 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 19EXPL: 0

An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455. Se ha descubierto un problema de autenticación indebida en WAGO PFC200 Series 3S CoDeSys Runtime, versiones 2.3.X y 2.4.X. Un atacante puede ejecutar diferentes operaciones remotas sin autenticación gracias a la aplicación CoDeSys Runtime, que está disponible en red por defecto en el puerto 2455. • https://ics-cert.us-cert.gov/advisories/ICSA-18-044-01 • CWE-287: Improper Authentication •

CVSS: 9.1EPSS: 0%CPEs: 7EXPL: 0

An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to edit and to view settings without authenticating. Ha sido descubierto un problema en WAGO 750-8202/PFC200 anterior a FW04 (publicado en agosto de 2015), WAGO 750-881 anterior a FW09 (publicado en agosto de 2016) y WAGO 0758-0874-0000-0111. Accediendo a un localizador de recursos uniforme (URL) específico en el servidor web, un usuario malicioso puede editar y ver la configuración sin autenticarse. • http://www.securityfocus.com/bid/95074 https://ics-cert.us-cert.gov/advisories/ICSA-16-357-02 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 9EXPL: 2

WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management. WAGO IO 750-849 01.01.27 y 01.02.05, WAGO IO 750-881, y WAGO IO 758-870 tienen una gestión de credenciales débil. WAGO IO PLC versions 758-870 and 750-849 suffer from weak credential management, lack of privilege separation, insecure ftp configuration, and weak filesystem permissions. • http://packetstormsecurity.com/files/136077/WAGO-IO-PLC-758-870-750-849-Credential-Management-Privilege-Separation.html http://seclists.org/fulldisclosure/2016/Mar/4 http://www.securityfocus.com/bid/84138 • CWE-255: Credentials Management Errors •

CVSS: 10.0EPSS: 0%CPEs: 5EXPL: 2

WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation. WAGO IO 750-849 01.01.27 y WAGO IO 750-881 01.02.05 no contienen separación de privilegios. WAGO IO PLC versions 758-870 and 750-849 suffer from weak credential management, lack of privilege separation, insecure ftp configuration, and weak filesystem permissions. • http://packetstormsecurity.com/files/136077/WAGO-IO-PLC-758-870-750-849-Credential-Management-Privilege-Separation.html http://seclists.org/fulldisclosure/2016/Mar/4 http://www.securityfocus.com/bid/84138 • CWE-254: 7PK - Security Features •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest for the guest account, which makes it easier for remote attackers to obtain login access via a TELNET session, a different vulnerability than CVE-2012-3013. La Consola Linux en WAGO I/O System 758 modelo 758-870, 758-874, y 758-875 Industrial PC (IPC), tienen una contraseña por defecto de wago para las cuentas (1) root y (2) admin, (3) una contraseña por defecto de user para la cuenta de usuario, y (4)y una contraseña por defecto de guest para la cuenta de invitado, lo que hace más fácil a atacantes remotos obtener acceso a través de una sessión TELNET, una vulnerabilidad diferente de CVE-2012-3013. • http://www.us-cert.gov/control_systems/pdf/ICSA-12-249-02.pdf http://www.wago.com/wagoweb/documentation/app_note/a1176/a117600e.pdf • CWE-255: Credentials Management Errors •