Information Exposure in WAGO PFC200 and PFC100 Firmware by WAGO
CVE-2019-5073
5.3MEDIUM
Summary
An information exposure vulnerability exists within the I/O-Check functionality of WAGO PFC200 and PFC100 Firmware, allowing attackers to exploit the iocheckd service. By sending specially crafted packets, an attacker may trigger uninitialized stack data to be copied into response packet buffers. This flaw can cause external tools to fail, potentially compromising data integrity when unprotected communications are exploited.
Affected Version(s)
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved