CVE Database
/

CVE-2025-1235

Back to search

CVE-2025-1235

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970.

VendorProductVersions

WAGO

Fully Managed Switches 0852-0303

affected
all

WAGO

Fully Managed Switches 0852-1305

affected
all

WAGO

Fully Managed Switches 0852-1305/0000-0001

affected
all

WAGO

Fully Managed Switches 0852-1505

affected
all

WAGO

Fully Managed Switches 0852-1505/0000-0001

affected
all

WAGO

Lean Managed Switches 0852-1812

affected
all

WAGO

Lean Managed Switches 0852-1812/0010-0000

affected
all

WAGO

Lean Managed Switches 0852-1813

affected
all

WAGO

Lean Managed Switches 0852-1813/0000-0001

affected
all

WAGO

Lean Managed Switches 0852-1813/0010-0000

affected
all

WAGO

Lean Managed Switches 0852-1813/0010-0001

affected
all

WAGO

Lean Managed Switches 0852-1816

affected
all

WAGO

Lean Managed Switches 0852-1816/0010-0000

affected
all

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now