← Back

CVE-2018-8836

nvd nist
Published: Apr 3, 2018Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Affected (8)

8 products
750 880 Firmware
750 881 Firmware
750 852 Firmware
750 882 Firmware
750 885 Firmware
750 831 Firmware
750 889 Firmware
750 829 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 880
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 881
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 852
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 882
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 885
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 831
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 889
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10
Running on/withPlatform Versions
Wago
750 829
All versions

Timeline

No history available yet.