CVE-2025-0101: WAGO: Year 2038 problem

6.5 CVSS

Description

A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.

Classification

CVE ID: CVE-2025-0101

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types

CWE-190 Integer Overflow or Wraparound

Affected Products

Vendor: WAGO

Product: CC100 0751-9x01, PFC100 G1 0750-810x/xxxx-xxxx, PFC100 G1 0750-810x/xxxx-xxxx, PFC100 G2 0750-811x-xxxx-xxxx, PFC100 G2 0750-811x-xxxx-xxxx, PFC200 G1 750-820x-xxx-xxx, PFC200 G1 750-820x-xxx-xxx, PFC200 G2 750-821x-xxx-xxx, PFC200 G2 750-821x-xxx-xxx, TP600 0762-420x/8000-000x, TP600 0762-420x/8000-000x, TP600 0762-430x/8000-000x, TP600 0762-430x/8000-000x, TP600 0762-520x/8000-000x, TP600 0762-520x/8000-000x, TP600 0762-530x/8000-000x, TP600 0762-530x/8000-000x, TP600 0762-620x/8000-000x, TP600 0762-620x/8000-000x, TP600 0762-630x/8000-000x, TP600 0762-630x/8000-000x, WAGO CC100 0751-9x01, WAGO Edge Controller 0752-8303/8000-0002, WAGO Edge Controller 0752-8303/8000-0002

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.37% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-0101
https://cert.vde.com/en/advisories/VDE-2025-007

Timeline