Command Injection Vulnerability in WAGO PFC 200 by WAGO
CVE-2019-5168

7.8HIGH

Key Information:

Vendor
Wago
Vendor
CVE Published:
11 March 2020

Summary

A command injection vulnerability has been identified in the I/O-Check function of the WAGO PFC 200. This flaw allows an attacker to craft a malicious XML cache file, which manipulates the domain name value. When processed, this value is improperly used within a command executed by the system, potentially leading to unauthorized command execution. Users of the affected versions are advised to take immediate action to secure their systems against potential exploitation.

Affected Version(s)

WAGO PFC200 Firmware version 03.02.02(14)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-5168 : Command Injection Vulnerability in WAGO PFC 200 by WAGO | SecurityVulnerability.io