Stack Buffer Overflow in WAGO PFC 200 Firmware Affects I/O-Check Service
CVE-2019-5180

7.8HIGH

Key Information:

Vendor
Wago
Vendor
CVE Published:
12 March 2020

Summary

A stack buffer overflow vulnerability exists in the iocheckd service’s I/O-Check functionality within the WAGO PFC 200 Firmware version 03.02.02(14). This vulnerability can be exploited by attackers who send specially crafted packets designed to manipulate the parsing of the cache file. Specifically, the overflow occurs in the destination buffer due to an inadequate handling of IP address values, where values exceeding a specific length lead to a potential crash of the service. Proper input validation is crucial to mitigate these risks and ensure the integrity and availability of the firmware.

Affected Version(s)

WAGO PFC200 Firmware version 03.02.02(14)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.