CVE-2024-1490

HIGH

Wago: Vulnerability in WBM through Open VPN

Title source: cna
STIX 2.1

Description

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

Scores

CVSS v3 7.2
EPSS 0.0073
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (13)
WAGO/CC100 (0751-9x01) 0.0.0 - 4.5.10
WAGO/Edge Controller (0752-8303-8000-0002) 0.0.0 - 4.5.10
WAGO/PFC100 G1 (0750-810-xxxx-xxxx) 0.0.0 - 3.10.10
WAGO/PFC100 G2 (0750-811x-xxxx-xxxx) 0.0.0 - 4.5.10
WAGO/PFC200 G1 (750-820x-xxxx-xxxx) 0.0.0 - 3.10.10
WAGO/PFC200 G2 (750-821x-xxxx-xxxx) 0.0.0 - 4.5.10
WAGO/TP600 (0762-420x-8000-000x) 0.0.0 - FW 26
WAGO/TP600 (0762-430x-8000-000x) 0.0.0 - 4.5.10
WAGO/TP600 (0762-520x-8000-000x) 0.0.0 - 4.5.10
WAGO/TP600 (0762-530x-8000-000x) 0.0.0 - 4.5.10
... and 3 more
Published Apr 09, 2026
Tracked Since Apr 09, 2026