CVE-2024-41974
WAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple Devices
Severity Score
7.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
*Credits:
Diego Giubertoni, Nozomi Networks
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-07-25 CVE Reserved
- 2024-11-18 CVE Published
- 2024-11-18 CVE Updated
- 2024-11-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2024-047 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
WAGO Search vendor "WAGO" | CC100 0751-9x01 Search vendor "WAGO" for product "CC100 0751-9x01" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "CC100 0751-9x01" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | PFC100 G2 0750-811x-xxxx-xxxx Search vendor "WAGO" for product "PFC100 G2 0750-811x-xxxx-xxxx" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "PFC100 G2 0750-811x-xxxx-xxxx" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | PFC200 G2 750-821x-xxx-xxx Search vendor "WAGO" for product "PFC200 G2 750-821x-xxx-xxx" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "PFC200 G2 750-821x-xxx-xxx" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-420x/8000-000x Search vendor "WAGO" for product "TP600 0762-420x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-420x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-430x/8000-000x Search vendor "WAGO" for product "TP600 0762-430x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-430x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-520x/8000-000x Search vendor "WAGO" for product "TP600 0762-520x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-520x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-530x/8000-000x Search vendor "WAGO" for product "TP600 0762-530x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-530x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-620x/8000-000x Search vendor "WAGO" for product "TP600 0762-620x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-620x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | TP600 0762-630x/8000-000x Search vendor "WAGO" for product "TP600 0762-630x/8000-000x" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "TP600 0762-630x/8000-000x" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
| ||||||
WAGO Search vendor "WAGO" | Edge Controller 0752-8303/8000-0002 Search vendor "WAGO" for product "Edge Controller 0752-8303/8000-0002" | >= 0.0.0 <= 4.5.10 (FW27) Search vendor "WAGO" for product "Edge Controller 0752-8303/8000-0002" and version " >= 0.0.0 <= 4.5.10 (FW27)" | en |
Affected
|