← All CVEs

CVE-2018-12980

high · 8.8

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

8.8
CVSS
29.8%
EPSS (exploit prob.)
98th
EPSS percentile
2018-07-12
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
wago762-3000_firmware< 02
wago762-3000all versions
wago762-3001_firmware< 02
wago762-3001all versions
wago762-3002_firmware< 02
wago762-3002all versions
wago762-3003_firmware< 02
wago762-3003all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-12980