Denial-of-Service Vulnerability in WAGO PFC 200 and PFC 100 Firmware
CVE-2019-5080

9.1CRITICAL

Key Information:

Vendor
Wago
Vendor
CVE Published:
18 December 2019

Summary

An exploitable denial-of-service vulnerability exists in the 'I/O-Check' functionality of WAGO’s iocheckd service for specific firmware versions of the PFC 200 and PFC 100 devices. An attacker can send a single, unauthenticated packet to trigger a denial of service, potentially overriding the device's credentials and reverting them to the default documented settings. This may leave the device vulnerable to further attacks, emphasizing the need for immediate security measures.

Affected Version(s)

WAGO PFC100 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.