CVE-2021-34593

HIGH

Wago 750-8202 Firmware < fw20 - Improper Exception Handling

Title source: rule

Description

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Scores

CVSS v3 7.5
EPSS 0.0159
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-755
Status published

Affected Products (15)

wago/750-8202_firmware < fw20
wago/750-8203_firmware < fw20
wago/750-8204_firmware < fw20
wago/750-8206_firmware < fw20
wago/750-8207_firmware < fw20
wago/750-8208_firmware < fw20
wago/750-8210_firmware < fw20
wago/750-8211_firmware < fw20
wago/750-8212_firmware < fw20
wago/750-8213_firmware < fw20
wago/750-8214_firmware < fw20
wago/750-8216_firmware < fw20
wago/750-8217_firmware < fw20
codesys/plcwinnt < 2.4.7.56
codesys/runtime_toolkit < 2.4.7.56

Timeline

Published Oct 26, 2021
Tracked Since Feb 18, 2026