An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.
2020-03-11T22:27:40.897
2024-11-21T04:44:27.557
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | wago | pfc200_firmware | 03.00.39\(12\) | Yes |
Operating System | wago | pfc200_firmware | 03.01.07\(13\) | Yes |
Operating System | wago | pfc200_firmware | 03.02.02\(14\) | Yes |
Hardware | wago | pfc200 | - | No |