CVE Intelligence
Skip to main content
HIGH

CVE-2024-1490

CVE-2024-1490 — Wago: Vulnerability in WBM through Open VPN

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

Published Updated Sources: cvelistV5, CERTVDE

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

wago

13 products listed

CVSS base

7.2

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Total

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (13)

cc100 0751 9x01pfc100 g1 0750 810 xxxx xxxxpfc100 g2 0750 811x xxxx xxxxpfc200 g1 750 820x xxxx xxxxpfc200 g2 750 821x xxxx xxxxtp600 0762 420x 8000 000xtp600 0762 430x 8000 000xtp600 0762 520x 8000 000xtp600 0762 530x 8000 000xtp600 0762 620x 8000 000xtp600 0762 630x 8000 000xedge controller 0752 8303 8000 0002wp400 0762 340x

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
7.2CVSS 3.1HIGHcvelistV5

Weakness & attack patterns

  • CWE-94

Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.

  • T1027.006Obfuscated Files or Information: HTML Smuggling
  • T1027.009Obfuscated Files or Information: Embedded Payloads
  • T1564.009Hide Artifacts: Resource Forking

References

2 on the record

Elsewhere on this site

  • wagoevery CVE for this vendor
  • CWE-94other pages naming this weakness

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.