ID

VAR-202211-0500


CVE

CVE-2021-34568


TITLE

plural  WAGO  Unlimited or Throttling Resource Allocation Vulnerability in the Product

Trust: 0.8

sources: JVNDB: JVNDB-2021-020494

DESCRIPTION

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service. 750-8100 firmware, 750-8101 firmware, 750-8101/025-000 firmware etc. WAGO The product contains a resource allocation vulnerability without limits or throttling.Service operation interruption (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2021-34568 // JVNDB: JVNDB-2021-020494

AFFECTED PRODUCTS

vendor:wagomodel:750-8202\/025-000scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4103scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4102scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4202\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-012scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6202\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/040-000scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4201\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6204\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-011scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6303\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-5205\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4305\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6302\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4206\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-012scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6202\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5203\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/025-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6303\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4204\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/040-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5306\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6302\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/025-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-011scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4104scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4101scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6201\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4302\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5303\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:752-8303\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4203\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4206\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5304\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8101\/025-000scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6203\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4202\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/040-000scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6204\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4205\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4305\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6301\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8101scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8102scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-5204\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5203\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-022scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8100scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4204\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/025-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4104scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4302\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8102scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8102\/025-000scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4203\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8101\/025-000scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4303\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4306\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5304\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6203\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/040-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4103scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4101scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4304\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-5305\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6301\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-5206\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4301\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4205\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4205\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/025-000scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8101scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8102\/025-000scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4206\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4201\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5204\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6304\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/000-022scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-5205\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-6304\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:750-8100scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4304\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4205\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4206\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-4102scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4303\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4306\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202\/025-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5306\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5305\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-6201\/8000-001scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5303\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:752-8303\/8000-002scope:ltversion:18

Trust: 1.0

vendor:wagomodel:762-5206\/8000-001scope:eqversion:18

Trust: 1.0

vendor:wagomodel:762-4301\/8000-002scope:eqversion:18

Trust: 1.0

vendor:wagomodel:750-8202/000-012scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8102scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8202/025-000scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8101/025-000scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8100scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8101scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8202/000-011scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8102/025-000scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8202scope: - version: -

Trust: 0.8

vendor:wagomodel:750-8202/000-022scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-020494 // NVD: CVE-2021-34568

CVSS

SEVERITY

CVSSV2

CVSSV3

info@cert.vde.com: CVE-2021-34568
value: HIGH

Trust: 1.0

OTHER: JVNDB-2021-020494
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202211-2421
value: HIGH

Trust: 0.6

info@cert.vde.com: CVE-2021-34568
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2021-020494
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-020494 // CNNVD: CNNVD-202211-2421 // NVD: CVE-2021-34568

PROBLEMTYPE DATA

problemtype:CWE-770

Trust: 1.0

problemtype:Allocation of resources without limits or throttling (CWE-770) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-020494 // NVD: CVE-2021-34568

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202211-2421

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202211-2421

PATCH

title:WAGO Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=213541

Trust: 0.6

sources: CNNVD: CNNVD-202211-2421

EXTERNAL IDS

db:NVDid:CVE-2021-34568

Trust: 3.2

db:CERT@VDEid:VDE-2020-036

Trust: 2.4

db:JVNDBid:JVNDB-2021-020494

Trust: 0.8

db:CNNVDid:CNNVD-202211-2421

Trust: 0.6

sources: JVNDB: JVNDB-2021-020494 // CNNVD: CNNVD-202211-2421 // NVD: CVE-2021-34568

REFERENCES

url:https://cert.vde.com/en/advisories/vde-2020-036/

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-34568

Trust: 1.4

url:https://cxsecurity.com/cveshow/cve-2021-34568/

Trust: 0.6

sources: JVNDB: JVNDB-2021-020494 // CNNVD: CNNVD-202211-2421 // NVD: CVE-2021-34568

SOURCES

db:JVNDBid:JVNDB-2021-020494
db:CNNVDid:CNNVD-202211-2421
db:NVDid:CVE-2021-34568

LAST UPDATE DATE

2024-08-14T14:02:14.352000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2021-020494date:2023-11-02T08:06:00
db:CNNVDid:CNNVD-202211-2421date:2022-11-11T00:00:00
db:NVDid:CVE-2021-34568date:2023-11-07T03:36:02.107

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2021-020494date:2023-11-02T00:00:00
db:CNNVDid:CNNVD-202211-2421date:2022-11-09T00:00:00
db:NVDid:CVE-2021-34568date:2022-11-09T16:15:12.077