Remote Code Execution Vulnerability in WAGO PFC200 Cloud Connectivity
CVE-2019-5161
9.1CRITICAL
Summary
A critical vulnerability in the Cloud Connectivity feature of WAGO PFC200 allows attackers to exploit the system by sending a specially crafted XML file. This enables the service to download and execute a shell script with root privileges, posing a significant risk to system integrity and security. Administrators are urged to assess and mitigate this vulnerability by applying necessary updates and implementing security best practices.
Affected Version(s)
WAGO PFC200 Firmware version 03.02.02(14)
WAGO PFC200 Firmware version 03.01.07(13)
WAGO PFC200 Firmware version 03.00.39(12)
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved