Share: Email | Twitter

ID

VDE-2021-014

Published

2021-05-20 11:08 (CEST)

Last update

2021-05-20 11:08 (CEST)

Vendor(s)

WAGO GmbH & Co. KG

Product(s)

Article No° Product Name Affected Version(s)
750-8202/xxx-xxx < 03.06.19 (18)
750-8203/xxx-xxx < 03.06.19 (18)
750-8204/xxx-xxx < 03.06.19 (18)
750-8206/xxx-xxx < 03.06.19 (18)
750-8207/xxx-xxx < 03.06.19 (18)
750-8208/xxx-xxx < 03.06.19 (18)
750-8210/xxx-xxx < 03.06.19 (18)
750-8211/xxx-xxx < 03.06.19 (18)
750-8212/xxx-xxx < 03.06.19 (18)
750-8213/xxx-xxx < 03.06.19 (18)
750-8214/xxx-xxx < 03.06.19 (18)
750-8216/xxx-xxx < 03.06.19 (18)
750-8217/xxx-xxx < 03.06.19 (18)
750-823 <= FW07
750-829 <= FW14
750-831/000-00x <= FW14
750-832/000-00x <= FW06
750-852 <= FW14
750-862 <= FW07
750-880/0xx-xxx <= FW15
750-881 <= FW14
750-882 <= FW14
750-885/0xx-xxx <= FW14
750-889 <= FW14
750-890/0xx-xxx <= FW07
750-891 <= FW07
750-893 <= FW07

Summary

Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC’s.

Vulnerabilities



Last Update
7. Juli 2021 11:07
Weakness
Incorrect Authorization (CWE-863)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
Last Update
7. Juli 2021 11:07
Weakness
Out-of-bounds Write (CWE-787)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
Last Update
28. September 2021 09:30
Weakness
Out-of-bounds Write (CWE-787)
Summary

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

Last Update
7. Juli 2021 11:07
Weakness
Out-of-bounds Write (CWE-787)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
Last Update
17. November 2022 13:09
Weakness
Missing Authentication for Critical Function (CWE-306)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
Last Update
7. Juli 2021 11:07
Weakness
Out-of-bounds Read (CWE-125)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
Last Update
28. September 2021 09:30
Weakness
Out-of-bounds Read (CWE-125)
Summary

CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.

Last Update
28. September 2021 09:31
Weakness
Out-of-bounds Write (CWE-787)
Summary

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

Last Update
7. Juli 2021 11:07
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
Summary
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
Last Update
7. Juli 2021 11:07
Weakness
Allocation of Resources Without Limits or Throttling (CWE-770)
Summary
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
Last Update
7. Juli 2021 11:07
Weakness
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Summary
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Last Update
7. Juli 2021 11:07
Weakness
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Summary
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

Impact

The reported vulnerabilities allow an attacker who has access to the device and is able to exploit the vulnerabilities, to manipulate and disrupt the CODESYS 2.3 Runtime.

Solution

WAGO recommends all effected users with CODESYS 2.3 Runtime PLCs to update to the firmware version listed below.

Series Ethernet Controller:

Article No. Fixed Version Available
750-823 >=FW08 June 2021
750-829 >=FW15 May 2021
750-831/000-00x
750-832/000-00x >=FW08 June 2021
750-852 >=FW15 May 2021
750-862 >=FW08 June 2021
750-880/0xx-xxx >=FW16 May 2021
750-881 >=FW15 May 2021
750-882
750-885/0xx-xxx
750-889
750-890/0xx-xxx >=FW08 June 2021
750-891
750-893

Series PFC200 Controller

Article No. Fixed Patch Patch
available
Fixed
Firmware
Firmware
approx.
available
750-8202/xxx-xxx >=03.06.19 (18) May 2021 >=FW19 August 2021
750-8203/xxx-xxx
750-8204/xxx-xxx
750-8206/xxx-xxx
750-8207/xxx-xxx
750-8208/xxx-xxx
750-8210/xxx-xxx
750-8211/xxx-xxx
750-8212/xxx-xxx
750-8213/xxx-xxx
750-8214/xxx-xxx
750-8216/xxx-xxx
750-8217/xxx-xxx

Mitigation

  1. Use general security best practices to protect systems from local and network attacks.
  2. Do not allow direct access to the device from untrusted networks.
  3. Update to the latest firmware according to the table in chapter solutions.
  4. Disable the CODESYS 2.3 Web-Visualisation and CODESYS 2.3 port 2455.

For further impact information and risk mitigation, please refer to the official CODESYS Advisory Website at https://www.codesys.com/security/security-reports.html

Reported by

These vulnerabilities were reported by

  • Vyacheslav Moskvin, JSC Positive Technologies
  • Anton Dorfman, JSC Positive Technologies
  • Sergey Fedonin, JSC Positive Technologies
  • Ivan Kurnakov, JSC Positive Technologies
  • Denis Goryushev, JSC Positive Technologies

Coordination done by CERT@VDE.