Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12549


WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.


Published

2019-06-17T17:15:11.070

Last Modified

2024-11-21T04:23:04.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System wago 852-303_firmware < 1.2.2.s0 Yes
Hardware wago 852-303 - No
Operating System wago 852-1305_firmware < 1.1.6.s0 Yes
Hardware wago 852-1305 - No
Operating System wago 852-1505_firmware < 1.1.5.s0 Yes
Hardware wago 852-1505 - No

References