CVE-2018-25108
WAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumption
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
Un atacante remoto no autenticado puede provocar un DoS en el controlador debido al consumo descontrolado de recursos.
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
*Credits:
Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), Florian Fischer (Hochschule Augsburg)
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-01-15 CVE Reserved
- 2025-01-16 CVE Published
- 2025-01-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2018-013 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
WAGO Search vendor "WAGO" | 750-8100 (Controller PFC100) Search vendor "WAGO" for product "750-8100 (Controller PFC100)" | <= 02.05.23(08) Search vendor "WAGO" for product "750-8100 (Controller PFC100)" and version " <= 02.05.23(08)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | 750-831 (Controller BACnet/IP) Search vendor "WAGO" for product "750-831 (Controller BACnet/IP)" | <= 01.02.29(09) Search vendor "WAGO" for product "750-831 (Controller BACnet/IP)" and version " <= 01.02.29(09)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | 750-880 (Controller ETH) Search vendor "WAGO" for product "750-880 (Controller ETH)" | <= 01.07.03(10) Search vendor "WAGO" for product "750-880 (Controller ETH)" and version " <= 01.07.03(10)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | 750-889 (Controller KNX IP) Search vendor "WAGO" for product "750-889 (Controller KNX IP)" | <= 01.07.13(10) Search vendor "WAGO" for product "750-889 (Controller KNX IP)" and version " <= 01.07.13(10)" | en |
Affected
|