ID

VAR-201408-0411


TITLE

WAGO I/O System CODESYS WebVisu Password Information Disclosure Vulnerability

Trust: 0.8

sources: IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05215

DESCRIPTION

The AGO IPC is a compact industrial PC that is suitable for control applications. WAGO I/O System CODESYS WebVisu has a password information disclosure vulnerability that allows attackers to gain access to further sensitive information

Trust: 0.99

sources: CNVD: CNVD-2014-05215 // BID: 68485 // IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05215

AFFECTED PRODUCTS

vendor:wagomodel:i/o systemscope:lteversion:<=v2.3.9.44

Trust: 0.8

vendor:wagomodel:wago-i/o-systemscope:eqversion:750-8840

Trust: 0.3

vendor:wagomodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05215 // BID: 68485

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-05215
value: MEDIUM

Trust: 0.6

IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2014-05215
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05215

THREAT TYPE

network

Trust: 0.3

sources: BID: 68485

TYPE

Design Error

Trust: 0.3

sources: BID: 68485

EXTERNAL IDS

db:BIDid:68485

Trust: 0.9

db:CNVDid:CNVD-2014-05215

Trust: 0.8

db:IVDid:730795E4-1EC3-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 730795e4-1ec3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05215 // BID: 68485

REFERENCES

url:http://www.securityfocus.com/bid/68485/info

Trust: 0.6

url:http://seclists.org/bugtraq/2014/jul/50

Trust: 0.6

url:https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140710-3_wago_controller_webvisu_password_disclosure_v10.txt

Trust: 0.3

url: http://www.wago.com/

Trust: 0.3

sources: CNVD: CNVD-2014-05215 // BID: 68485

CREDITS

C. Kudera and S. Riegler of SEC Consult Vulnerability Lab

Trust: 0.3

sources: BID: 68485

SOURCES

db:IVDid:730795e4-1ec3-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-05215
db:BIDid:68485

LAST UPDATE DATE

2022-05-17T01:55:54.849000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-05215date:2014-08-26T00:00:00
db:BIDid:68485date:2014-04-10T00:00:00

SOURCES RELEASE DATE

db:IVDid:730795e4-1ec3-11e6-abef-000c29c66e3ddate:2014-08-26T00:00:00
db:CNVDid:CNVD-2014-05215date:2014-08-26T00:00:00
db:BIDid:68485date:2014-04-10T00:00:00