Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-1150— WAGO: Series 750-3x/-8x prone to MODBUS server DoS

CVSS 7.5 · High EPSS 0.30% · P53
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-1150

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WAGO: Series 750-3x/-8x prone to MODBUS server DoS
Source: NVD (National Vulnerability Database)
Vulnerability Description
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
对已超过有效生命周期的资源丧失索引
Source: NVD (National Vulnerability Database)
Vulnerability Title
wago 750-8xx 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WAGO wago 750-8xx是德国万可(WAGO)公司的一系列可编程逻辑控制器。该设备专门为在工业环境下应用而设计的数字运算操作电子系统。 WAGO 750-3x/-8x存在资源管理错误漏洞,该漏洞源于资源消耗不受控制。攻击者利用该漏洞通过使用特制数据包对 MODBUS 服务器进行拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
WAGO750-332 0 ~ FW10 -
WAGO750-362/xxx-xxx 0 ~ FW10 -
WAGO750-363/xxx-xxx 0 ~ FW10 -
WAGO750-364/xxx-xxx 0 ~ FW10 -
WAGO750-365/xxx-xxx 0 ~ FW10 -
WAGO750-823 0 ~ FW10 -
WAGO750-832/xxx-xxx 0 ~ FW10 -
WAGO750-862 0 ~ FW10 -
WAGO750-890/xxx-xxx 0 ~ FW10 -
WAGO750-891 0 ~ FW10 -
WAGO750-893 0 ~ FW10 -

II. Public POCs for CVE-2023-1150

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-1150

登录查看更多情报信息。

Same Patch Batch · WAGO · 2023-06-26 · 3 CVEs total

CVE-2023-16204.9 MEDIUMWAGO: DoS in multiple products in multiple versions using Codesys
CVE-2023-16194.9 MEDIUMWAGO: DoS in multiple versions of multiple products

IV. Related Vulnerabilities

V. Comments for CVE-2023-1150

No comments yet


Leave a comment