Command Injection Vulnerability in WAGO PFC 200 by WAGO
CVE-2019-5168
7.8HIGH
What is CVE-2019-5168?
A command injection vulnerability has been identified in the I/O-Check function of the WAGO PFC 200. This flaw allows an attacker to craft a malicious XML cache file, which manipulates the domain name value. When processed, this value is improperly used within a command executed by the system, potentially leading to unauthorized command execution. Users of the affected versions are advised to take immediate action to secure their systems against potential exploitation.
Affected Version(s)
WAGO PFC200 Firmware version 03.02.02(14)