Heap Buffer Overflow in WAGO PFC200 and PFC100 Firmware by WAGO
CVE-2019-5079
9.8CRITICAL
Summary
A heap buffer overflow vulnerability has been identified in the I/O-Check functionality of the WAGO PFC200 and PFC100 firmware. This flaw allows attackers to send specially crafted packets, potentially leading to unauthorized code execution. The affected firmware versions for the PFC200 include 03.01.07(13) and 03.00.39(12), while the PFC100 is affected at version 03.00.39(12). This vulnerability poses significant risks to the integrity and security of connected systems, making it crucial for users to apply updates or patches to mitigate the risk of exploitation.
Affected Version(s)
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved