Article No° | Product Name | Affected Version(s) |
---|---|---|
Basic Controller 0750-8001 | <= 01.03.03 (FW3) | |
Basic Controller 0751-8000 | <= 01.03.03 (FW3) |
The following firmware versions installed on several devices are vulnerable due to a vulnerability in the CODESYS Control V3 web server.
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
The configuration UI called web based management is part of the Control runtime system and is also used for the visualization of running applications. Because the web server does not correctly check the return value of an underlying function, it reacts in a wrong way to specifically crafted TLS packets that are received via an HTTPS connection. This causes the web server to access invalid memory and the web server task to crash.
Remediation
Update to Firmware version 01.04.07 (FW4).
CERT@VDE coordinated with WAGO GmbH & Co. KG