CVE-2018-8836 Vulnerability Details

  /     /     /  

CVE-2018-8836 Metadata Quick Info

CVE Published: 03/04/2018 | CVE Updated: 17/09/2024 | CVE Year: 2018
Source: icscert | Vendor: WAGO | Product: WAGO 750 Series
Status : PUBLISHED

CVE-2018-8836 Description

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-404
CWE Name: IMPROPER RESOURCE SHUTDOWN OR RELEASE CWE-404
Source: WAGO

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).