Improper Host Validation Vulnerability in WAGO PFC200 Firmware
CVE-2019-5160

9.1CRITICAL

Key Information:

Vendor

Wago

Vendor
CVE Published:
11 March 2020

What is CVE-2019-5160?

An improper host validation vulnerability exists in the Cloud Connectivity functionality of the WAGO PFC200 Firmware. Specifically, the flaw allows an attacker to exploit the system by sending a specially crafted HTTPS POST request. This causes the software to connect to an unauthorized host, potentially compromising the firmware update process. By directing the Cloud Connectivity software to connect to a malicious Azure IoT Hub node, an attacker may gain unauthorized access to sensitive functionalities, posing a significant risk to system integrity.

Affected Version(s)

WAGO PFC200 Firmware version 03.02.02(14)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.