CVE-2025-0101: WAGO: Year 2038 problem
A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0101?
CVE-2025-0101 is considered a low severity vulnerability affecting device date settings.
What is the impact of CVE-2025-0101?
CVE-2025-0101 allows a low privileged user to change the device date to January 19, 2038, causing functions to fail or behave unexpectedly.
How do I fix CVE-2025-0101?
To resolve CVE-2025-0101, ensure that devices have access controls preventing low-privileged users from changing system dates.
Which software is affected by CVE-2025-0101?
CVE-2025-0101 affects WAGO devices that are vulnerable to the Year 2038 problem.
What should be monitored due to CVE-2025-0101?
It is important to monitor the device functionality and access logs for suspicious date changes related to CVE-2025-0101.