{
    "document": {
        "acknowledgments": [
            {
                "organization": "CERT@VDE",
                "summary": "coordination",
                "urls": [
                    "https://certvde.com"
                ]
            },
            {
                "summary": "reported",
                "organization": "Uwe Disch"
            }
        ],
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp/"
            }
        },
        "lang": "en-US",
        "notes": [
            {
                "category": "summary",
                "text": "WAGO controllers have always been designed for easy connection to IT infrastructure. Even controllers from legacy product lines support encryption standards to ensure secure communication.\nWith special crafted requests it is possible to bring the device out of operation.\nAll listed devices are vulnerable for this denial of service attack.",
                "title": "Summary"
            },
            {
                "title": "Remediation",
                "text": "Update the device to the latest FW version.",
                "category": "description"
            },
            {
                "category": "description",
                "title": "Impact",
                "text": "This vulnerability allows an attacker who has access to the device to send a series of maliciously constructed packets which can bring the device out of operation. The device needs a power on reset to go back to normal operation."
            },
            {
                "text": "- Restrict network access to the device.\n- Do not directly connect the device to the internet\n- Disable unused TCP/UDP-ports\n- Disable Web Based Management ports 80/443 after configuration phase.",
                "title": "Mitigation",
                "category": "description"
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "psirt@wago.com",
            "name": "WAGO GmbH & Co. KG",
            "namespace": "https://www.wago.com/psirt"
        },
        "references": [
            {
                "category": "external",
                "summary": "WAGO advisory overview at CERT@VDE",
                "url": "https://certvde.com/en/advisories/vendor/wago/"
            },
            {
                "category": "self",
                "summary": "VDE-2021-038: WAGO: OpenSSL DoS Vulnerability in PLCs - HTML",
                "url": "https://certvde.com/en/advisories/VDE-2021-038"
            },
            {
                "summary": "VDE-2021-038: WAGO: OpenSSL DoS Vulnerability in PLCs - CSAF",
                "url": "https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-038.json",
                "category": "self"
            }
        ],
        "title": "WAGO: OpenSSL DoS Vulnerability in PLCs",
        "tracking": {
            "aliases": [
                "VDE-2021-038"
            ],
            "current_release_date": "2025-05-14T12:53:43.000Z",
            "generator": {
                "date": "2025-01-27T09:56:53.497Z",
                "engine": {
                    "name": "Secvisogram",
                    "version": "2.5.17"
                }
            },
            "id": "VDE-2021-038",
            "initial_release_date": "2021-08-31T07:00:00.000Z",
            "revision_history": [
                {
                    "date": "2021-08-31T07:00:00.000Z",
                    "number": "1",
                    "summary": "Initial revision."
                },
                {
                    "number": "2",
                    "summary": "Fix: version space, added distribution",
                    "date": "2025-05-14T12:53:43.000Z"
                }
            ],
            "status": "final",
            "version": "2"
        }
    },
    "product_tree": {
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "summary": "Affected Products.",
                "product_ids": [
                    "CSAFPID-31001",
                    "CSAFPID-31002",
                    "CSAFPID-31003",
                    "CSAFPID-31004"
                ]
            }
        ],
        "branches": [
            {
                "category": "vendor",
                "name": "WAGO",
                "branches": [
                    {
                        "name": "Hardware",
                        "category": "product_family",
                        "branches": [
                            {
                                "name": "750-831/xxx-xxx",
                                "category": "product_name",
                                "product": {
                                    "name": "750-831/xxx-xxx",
                                    "product_id": "CSAFPID-11001"
                                }
                            },
                            {
                                "name": "750-880/xxx-xxx",
                                "category": "product_name",
                                "product": {
                                    "product_id": "CSAFPID-11002",
                                    "name": "750-880/xxx-xxx"
                                }
                            },
                            {
                                "name": "750-881",
                                "category": "product_name",
                                "product": {
                                    "name": "750-881",
                                    "product_id": "CSAFPID-11003"
                                }
                            },
                            {
                                "name": "750-889",
                                "category": "product_name",
                                "product": {
                                    "name": "750-889",
                                    "product_id": "CSAFPID-11004"
                                }
                            }
                        ]
                    },
                    {
                        "name": "Firmware",
                        "category": "product_family",
                        "branches": [
                            {
                                "name": "<=FW15",
                                "category": "product_version_range",
                                "product": {
                                    "name": "Firmware <=FW15",
                                    "product_id": "CSAFPID-21001"
                                }
                            }
                        ]
                    }
                ]
            }
        ],
        "relationships": [
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11001",
                "full_product_name": {
                    "name": "Firmware <=FW15 installed on 750-831/xxx-xxx",
                    "product_id": "CSAFPID-31001"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11002",
                "full_product_name": {
                    "name": "Firmware <=FW15 installed on 750-880/xxx-xxx",
                    "product_id": "CSAFPID-31002"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11003",
                "full_product_name": {
                    "name": "Firmware <=FW15 installed on 750-881",
                    "product_id": "CSAFPID-31003"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "relates_to_product_reference": "CSAFPID-11004",
                "full_product_name": {
                    "name": "Firmware <=FW15 installed on 750-889",
                    "product_id": "CSAFPID-31004"
                }
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2021-34581",
            "title": "CVE-2021-34581",
            "cwe": {
                "id": "CWE-772",
                "name": "Missing Release of Resource after Effective Lifetime"
            },
            "notes": [
                {
                    "title": "Vulnerability Description",
                    "category": "description",
                    "text": "Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device."
                }
            ],
            "remediations": [
                {
                    "details": "- Restrict network access to the device.\n- Do not directly connect the device to the internet\n- Disable unused TCP/UDP-ports\n- Disable Web Based Management ports 80/443 after configuration phase.",
                    "category": "mitigation",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                },
                {
                    "details": "Update the device to the latest FW version.",
                    "category": "vendor_fix",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "temporalScore": 7.5,
                        "temporalSeverity": "HIGH",
                        "environmentalScore": 7.5,
                        "environmentalSeverity": "HIGH",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "HIGH"
                    },
                    "products": [
                        "CSAFPID-31001",
                        "CSAFPID-31002",
                        "CSAFPID-31003",
                        "CSAFPID-31004"
                    ]
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-31001",
                    "CSAFPID-31002",
                    "CSAFPID-31003",
                    "CSAFPID-31004"
                ]
            }
        }
    ]
}