Improper Host Validation Vulnerability in WAGO PFC200 Firmware
CVE-2019-5160
9.1CRITICAL
Summary
An improper host validation vulnerability exists in the Cloud Connectivity functionality of the WAGO PFC200 Firmware. Specifically, the flaw allows an attacker to exploit the system by sending a specially crafted HTTPS POST request. This causes the software to connect to an unauthorized host, potentially compromising the firmware update process. By directing the Cloud Connectivity software to connect to a malicious Azure IoT Hub node, an attacker may gain unauthorized access to sensitive functionalities, posing a significant risk to system integrity.
Affected Version(s)
WAGO PFC200 Firmware version 03.02.02(14)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved