CVE-2021-34581
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-772
- Affected
- wago/750-880\/040-000 firmware · wago/750-880\/025-002 firmware · wago/750-880\/025-001 firmware · wago/750-880\/025-000 firmware · wago/750-831\/000-002 firmware · wago/750-889 firmware · wago/750-881 firmware · wago/750-831 firmware · wago/750-880 firmware
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en-us/advisories/vde-2021-038Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-038Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.