Information Exposure in WAGO PFC200 and PFC100 Firmware by WAGO
CVE-2019-5073

5.3MEDIUM

Key Information:

Vendor
Wago
Vendor
CVE Published:
18 December 2019

Summary

An information exposure vulnerability exists within the I/O-Check functionality of WAGO PFC200 and PFC100 Firmware, allowing attackers to exploit the iocheckd service. By sending specially crafted packets, an attacker may trigger uninitialized stack data to be copied into response packet buffers. This flaw can cause external tools to fail, potentially compromising data integrity when unprotected communications are exploited.

Affected Version(s)

WAGO PFC100 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.