Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-38371 |
CWE-ID | CWE-400 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
WAGO PLC Series 750-893 Hardware solutions / Firmware WAGO PLC Series 750-891 Hardware solutions / Firmware WAGO PLC Series 750-890 Hardware solutions / Firmware WAGO PLC Series 750-885 Hardware solutions / Firmware WAGO PLC Series 750-882 Hardware solutions / Firmware WAGO PLC Series 750-862 Hardware solutions / Firmware WAGO PLC Series 750-832 Hardware solutions / Firmware WAGO PLC Series 750-829 Hardware solutions / Firmware WAGO PLC Series 750-823 Hardware solutions / Firmware WAGO PLC Series 750-365 Hardware solutions / Firmware WAGO PLC Series 750-364 Hardware solutions / Firmware WAGO PLC Series 750-363 Hardware solutions / Firmware WAGO PLC Series 750-362 Hardware solutions / Firmware WAGO PLC Series 750-332 Hardware solutions / Firmware WAGO PLC Series 750-330 Hardware solutions / Firmware WAGO PLC Series 750-889 Hardware solutions / Firmware WAGO PLC Series 750-881 Hardware solutions / Firmware WAGO PLC Series 750-880 Hardware solutions / Firmware WAGO PLC Series 750-852 Hardware solutions / Firmware WAGO PLC Series 750-831 Hardware solutions / Firmware WAGO PLC Series 750-352 Hardware solutions / Firmware |
Vendor | WAGO |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU68283
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-38371
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the FTP server. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website once available.
WAGO PLC Series 750-893: All versions
WAGO PLC Series 750-891: All versions
WAGO PLC Series 750-890: All versions
WAGO PLC Series 750-885: All versions
WAGO PLC Series 750-882: All versions
WAGO PLC Series 750-862: All versions
WAGO PLC Series 750-832: All versions
WAGO PLC Series 750-829: All versions
WAGO PLC Series 750-823: All versions
WAGO PLC Series 750-365: All versions
WAGO PLC Series 750-364: All versions
WAGO PLC Series 750-363: All versions
WAGO PLC Series 750-362: All versions
WAGO PLC Series 750-332: All versions
WAGO PLC Series 750-330: All versions
WAGO PLC Series 750-889: All versions
WAGO PLC Series 750-881: All versions
WAGO PLC Series 750-880: All versions
WAGO PLC Series 750-852: All versions
WAGO PLC Series 750-831: All versions
WAGO PLC Series 750-352: All versions
External linksQ & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.