Improper Authentication in WAGO PFC200 Series CoDeSys Runtime
CVE-2018-5459
What is CVE-2018-5459?
The WAGO PFC200 Series CoDeSys Runtime versions 2.3.X and 2.4.X has a vulnerability that allows an attacker to perform unauthorized remote operations. The issue arises from improper authentication, which exposes the CoDeSys Runtime application, accessible through network port 2455 by default. Attackers can exploit this flaw to execute various unauthenticated commands, including reading, writing, or deleting files, as well as manipulating the PLC application during runtime by sending specially crafted TCP packets.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WAGO PFC200 Series WAGO PFC200 Series
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
