Denial of Service Vulnerability in WAGO PFC Series Firmware
CVE-2019-5078

9.1CRITICAL

Key Information:

Vendor
Wago
Vendor
CVE Published:
18 December 2019

Summary

An exploitable denial of service vulnerability exists in the 'I/O-Check' functionality of the iocheckd service in certain WAGO PFC200 and PFC100 firmware versions. An attacker can send a specially crafted set of packets, which may lead to the device entering an error state, disrupting all network communications. This vulnerability presents a significant risk to operational continuity, as devices can be rendered inoperable without proper mitigation.

Affected Version(s)

WAGO PFC100 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.