A couple of vulnerabilities discovered in industrial controllers made by WAGO, a German company specializing in electrical connection and automation solutions, can be exploited to disrupt technological processes, which in some cases could lead to industrial accidents, according to Russian cybersecurity firm Positive Technologies.
The vulnerabilities were found in the WAGO PFC200 programmable logic controller (PLC) and they have been patched by the vendor. One of flaws, tracked as CVE-2021-21001 and rated critical severity, has been described as a path traversal issue related to a CODESYS component used by the device. It allows an authenticated attacker with network access to the targeted device to access its file system with elevated privileges, by sending specially crafted packets.
“By exploiting this vulnerability, attackers can access the controller file system with read and write rights. Changes in the PLC file system may cause disruption of technological processes and even lead to industrial accidents,” explained Vladimir Nazarov, head of ICS security at Positive Technologies.
The second issue, identified as CVE-2021-21000 and rated medium severity, impacts WAGO’s iocheckd service, which is designed to check PLC input/output and display the PLC configuration. An unauthenticated attacker with network access to the device can leverage this flaw to cause a DoS condition.
“Exploitation may cause a sudden shutdown of the controller, and in turn interrupt technological processes,” Positive Technologies explained.
Learn more about vulnerabilities in industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series
These vulnerabilities were disclosed in May by Germany’s VDE CERT alongside 10 other security holes discovered by Positive Technologies in CODESYS industrial automation software.
The 10 CODESYS vulnerabilities — a majority rated critical and high severity — impacted industrial control system (ICS) products from more than a dozen vendors that use CODESYS software.
Positive Technologies was sanctioned recently by the U.S. government for allegedly supporting Russian intelligence agencies. However, the company said it will continue to responsibly disclose the vulnerabilities found by its employees in the products of major U.S. companies.
Related: Critical Flaw in WAGO PLC Exposes Organizations to Attacks
Related: Tens of Vulnerabilities Expose WAGO Controllers, HMI Panels to Attacks
Related: Several Critical Vulnerabilities Found in WAGO Controllers

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- 3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component
- OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023
- Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors
- ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation
- Thousands Access Fake DDoS-for-Hire Websites Set Up by UK Police
- Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform
- Dole Says Employee Information Compromised in Ransomware Attack
- High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian
Latest News
- 3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component
- UK Introduces Mass Surveillance With Online Safety Bill
- Musk, Scientists Call for Halt to AI Race Sparked by ChatGPT
- Malware Hunters Spot Supply Chain Attack Hitting 3CX Desktop App
- LeapXpert Banks $22M Funding to Secure Corporate Messaging With Consumer Apps
- Blockchain Security Firm True I/O Raises $9 Million
- Spera Banks $10 Million to Tackle Identity and Access Sprawl
- OpenAI Patches Account Takeover Vulnerabilities in ChatGPT
