SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-21001

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

MEDIUM 6.5EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.13% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
wago/750-823 firmware · wago/750-829 firmware · wago/750-831 firmware · wago/750-832 firmware · wago/750-852 firmware · wago/750-862 firmware · wago/750-880 firmware · wago/750-881 firmware · wago/750-882 firmware · wago/750-885 firmware · wago/750-889 firmware · wago/750-890 firmware · wago/750-891 firmware · wago/750-893 firmware · wago/750-8202 firmware · wago/750-8203 firmware · wago/750-8204 firmware · wago/750-8206 firmware · wago/750-8207 firmware · wago/750-8208 firmware · +7 more
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.