Vulnerability Details CVE-2018-8836
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.033
EPSS Ranking 86.6%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-8836
-
-
-
-
-
-
-
-
-
cpe:2.3:o:wago:750-829_firmware:-
-
cpe:2.3:o:wago:750-829_firmware:09
-
cpe:2.3:o:wago:750-829_firmware:10
-
cpe:2.3:o:wago:750-831_firmware:-
-
cpe:2.3:o:wago:750-831_firmware:09
-
cpe:2.3:o:wago:750-831_firmware:10
-
cpe:2.3:o:wago:750-852_firmware:-
-
cpe:2.3:o:wago:750-852_firmware:10
-
cpe:2.3:o:wago:750-880_firmware:-
-
cpe:2.3:o:wago:750-880_firmware:10
-
cpe:2.3:o:wago:750-881_firmware:-
-
cpe:2.3:o:wago:750-881_firmware:01.01.27
-
cpe:2.3:o:wago:750-881_firmware:01.02.05
-
cpe:2.3:o:wago:750-881_firmware:10
-
cpe:2.3:o:wago:750-882_firmware:-
-
cpe:2.3:o:wago:750-882_firmware:10
-
cpe:2.3:o:wago:750-885_firmware:-
-
cpe:2.3:o:wago:750-885_firmware:10
-
cpe:2.3:o:wago:750-889_firmware:-
-
cpe:2.3:o:wago:750-889_firmware:10