Back to overview

CVE-2021-20998

CRITICAL
10.0
CVSS 3.1
Description
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

Metadata

CVE ID
CVE-2021-20998
State
PUBLISHED
Assigner
CERTVDE
Reserved
2020-12-17 00:00 UTC
Published
2021-05-13 13:45 UTC
Last updated
2024-09-17 00:51 UTC
Primary CWE
CWE-306
CWE-306 Missing Authentication for Critical Function
Vendor / Product
WAGO / 0852-0303
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (5)
VendorProductPlatformVersions
WAGO 0852-0303 unspecified ≤ V1.2.3.S0
WAGO 0852-1305 unspecified ≤ V1.1.7.S0
WAGO 0852-1305/000-001 unspecified ≤ V1.0.4.S0
WAGO 0852-1505 unspecified ≤ V1.1.6.S0
WAGO 0852-1505/000-001 unspecified ≤ V1.0.4.S0
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306 Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview