Stack Buffer Overflow in WAGO PFC200 Firmware Command Line Utility
CVE-2019-5075

9.8CRITICAL

Key Information:

Vendor
Wago
Vendor
CVE Published:
18 December 2019

Summary

An exploitable stack buffer overflow vulnerability exists within the command line utility 'getcouplerdetails' of WAGO’s PFC200 and PFC100 Firmware. By sending specially crafted packets to the 'iocheckd' service, specifically designed to exploit the I/O-Check, an attacker can trigger a stack buffer overflow within the subprocess, potentially leading to arbitrary code execution. This vulnerability may be exploited without authentication, emphasizing the need for urgent security measures and patches by affected users.

Affected Version(s)

WAGO PFC100 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.