Stack Buffer Overflow Vulnerability in WAGO PFC 200 Firmware
CVE-2019-5176

5.5MEDIUM

Key Information:

Vendor
Wago
Vendor
CVE Published:
12 March 2020

Summary

A stack buffer overflow vulnerability exists in the iocheckd service's 'I/O-Check' functionality of WAGO PFC 200 Firmware version 03.02.02(14). This vulnerability allows an attacker to send specially crafted packets that overflow the destination buffer during the parsing of cache files. When a gateway value exceeds a specific length, it exceeds the buffer limit, leading to service crashes. The improper handling of these values can be exploited, affecting the stability and security of the device.

Affected Version(s)

WAGO PFC200 Firmware version 03.02.02(14)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.