Improper Host Validation Vulnerability in WAGO PFC200 Firmware
CVE-2019-5160
9.1CRITICAL
What is CVE-2019-5160?
An improper host validation vulnerability exists in the Cloud Connectivity functionality of the WAGO PFC200 Firmware. Specifically, the flaw allows an attacker to exploit the system by sending a specially crafted HTTPS POST request. This causes the software to connect to an unauthorized host, potentially compromising the firmware update process. By directing the Cloud Connectivity software to connect to a malicious Azure IoT Hub node, an attacker may gain unauthorized access to sensitive functionalities, posing a significant risk to system integrity.
Affected Version(s)
WAGO PFC200 Firmware version 03.02.02(14)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)