Command Injection Vulnerability in WAGO PFC200 Products
CVE-2019-5156
7.2HIGH
What is CVE-2019-5156?
A command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 products. This flaw allows an attacker to inject harmful operating system commands into the TimeoutPrepared parameter of the firmware update command, potentially compromising the device's integrity and security.
Affected Version(s)
WAGO PFC200 Firmware version 03.02.02(14)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)