ID

VAR-202105-0535


CVE

CVE-2021-21000


TITLE

plural  WAGO  Vulnerability in product allocation of resource allocation without limitation or throttling on devices

Trust: 0.8

sources: JVNDB: JVNDB-2021-007238

DESCRIPTION

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. plural WAGO Product devices contain vulnerabilities in resource allocation without restrictions or throttling.Denial of service (DoS) It may be put into a state

Trust: 1.71

sources: NVD: CVE-2021-21000 // JVNDB: JVNDB-2021-007238 // VULMON: CVE-2021-21000

AFFECTED PRODUCTS

vendor:wagomodel:750-8216scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-889scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-8207scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-8211scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-862scope:lteversion:fw07

Trust: 1.0

vendor:wagomodel:750-832scope:lteversion:fw06

Trust: 1.0

vendor:wagomodel:750-8213scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-881scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-831scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-882scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-893scope:lteversion:fw07

Trust: 1.0

vendor:wagomodel:750-852scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-8203scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-8206scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-885scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-8210scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-890scope:lteversion:fw07

Trust: 1.0

vendor:wagomodel:750-8214scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-829scope:lteversion:fw14

Trust: 1.0

vendor:wagomodel:750-8202scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-823scope:lteversion:fw07

Trust: 1.0

vendor:wagomodel:750-8208scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-880scope:lteversion:fw15

Trust: 1.0

vendor:wagomodel:750-8212scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-8217scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-8204scope:ltversion:03.06.19_\(18\)

Trust: 1.0

vendor:wagomodel:750-891scope:lteversion:fw07

Trust: 1.0

vendor:ワゴジャパン株式会社model:750-885scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-823scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-882scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-881scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-831scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-829scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-862scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-832scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-880scope: - version: -

Trust: 0.8

vendor:ワゴジャパン株式会社model:750-852scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-007238 // NVD: CVE-2021-21000

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-21000
value: HIGH

Trust: 1.0

info@cert.vde.com: CVE-2021-21000
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-21000
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202105-1455
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-21000
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-21000
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

info@cert.vde.com: CVE-2021-21000
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2021-21000
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-007238 // CNNVD: CNNVD-202105-1455 // NVD: CVE-2021-21000 // NVD: CVE-2021-21000

PROBLEMTYPE DATA

problemtype:CWE-770

Trust: 1.0

problemtype:Allocation of resources without limits or throttling (CWE-770) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-007238 // NVD: CVE-2021-21000

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202105-1455

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202105-1455

PATCH

title:Top Pageurl:https://www.wago.com/us/

Trust: 0.8

title:WAGO Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=152368

Trust: 0.6

sources: JVNDB: JVNDB-2021-007238 // CNNVD: CNNVD-202105-1455

EXTERNAL IDS

db:NVDid:CVE-2021-21000

Trust: 3.3

db:CERT@VDEid:VDE-2021-014

Trust: 2.5

db:JVNDBid:JVNDB-2021-007238

Trust: 0.8

db:CNNVDid:CNNVD-202105-1455

Trust: 0.6

db:VULMONid:CVE-2021-21000

Trust: 0.1

sources: VULMON: CVE-2021-21000 // JVNDB: JVNDB-2021-007238 // CNNVD: CNNVD-202105-1455 // NVD: CVE-2021-21000

REFERENCES

url:https://cert.vde.com/en-us/advisories/vde-2021-014

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-21000

Trust: 0.8

url:https://cert.vde.com/en/advisories/vde-2021-014/

Trust: 0.8

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-21000 // JVNDB: JVNDB-2021-007238 // CNNVD: CNNVD-202105-1455 // NVD: CVE-2021-21000

SOURCES

db:VULMONid:CVE-2021-21000
db:JVNDBid:JVNDB-2021-007238
db:CNNVDid:CNNVD-202105-1455
db:NVDid:CVE-2021-21000

LAST UPDATE DATE

2024-08-14T15:38:03.197000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-21000date:2021-05-24T00:00:00
db:JVNDBid:JVNDB-2021-007238date:2022-02-07T02:26:00
db:CNNVDid:CNNVD-202105-1455date:2021-05-31T00:00:00
db:NVDid:CVE-2021-21000date:2021-05-28T15:11:31.460

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-21000date:2021-05-24T00:00:00
db:JVNDBid:JVNDB-2021-007238date:2022-02-07T00:00:00
db:CNNVDid:CNNVD-202105-1455date:2021-05-24T00:00:00
db:NVDid:CVE-2021-21000date:2021-05-24T11:15:07.917