Remote Code Execution Vulnerability in WAGO PFC200 Cloud Connectivity
CVE-2019-5161

9.1CRITICAL

Key Information:

Vendor
Wago
Vendor
CVE Published:
11 March 2020

Summary

A critical vulnerability in the Cloud Connectivity feature of WAGO PFC200 allows attackers to exploit the system by sending a specially crafted XML file. This enables the service to download and execute a shell script with root privileges, posing a significant risk to system integrity and security. Administrators are urged to assess and mitigate this vulnerability by applying necessary updates and implementing security best practices.

Affected Version(s)

WAGO PFC200 Firmware version 03.02.02(14)

WAGO PFC200 Firmware version 03.01.07(13)

WAGO PFC200 Firmware version 03.00.39(12)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.