CVE-2024-12650 Details
Description
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications.
A vulnerability exists in the WAGO PFC firmware SDK-G2 component of libwagosnmp, affecting several WAGO products, including various PFC, Edge Controller, and TP600 models, all prior to specific firmware versions. This vulnerability allows an attacker with low privileges to manipulate requested memory sizes, causing the application to access invalid memory areas. The result is a crash of the application, although other applications remain unaffected.
Users are advised to update to Firmware 4.7.1 (FW29) or Firmware 03.10.11. For the latest Custom Firmware, please contact WAGO support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 5, 2025CISA-ADP
Assessed Mar 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2025-004 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-252 | Unchecked Return Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WAGO CC100 0751-9x01 | < 04.07.01 (FW29) < 04.07.01 (70) |
CPE
Remediation
| |
| WAGO Edge Controller 0752-8303 | < 04.07.01 (FW29) < 04.07.01 (70) |
CPE
Remediation
| |
| WAGO PFC100 G1 0750-810x | < 3.10.11 (FW22 Patch 2) < 04.07.01 (70) |
CPE
Remediation
| |
| WAGO PFC100 G2 0750-811x | All versions |
CPE
Remediation
| |
| WAGO PFC200 G1 750-820x | < 3.10.11 (FW22 Patch 2) < 04.07.01 (70) < 04.07.01 (FW29) |
CPE
Remediation
| |
| WAGO PFC200 G2 750-821x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-420x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-430x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-520x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-530x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-620x | All versions |
CPE
Remediation
| |
| WAGO TP600 0762-630x | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2025 | New CVE Received | [email protected] |
Volerion