Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5157


An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.


Published

2020-03-11T22:27:40.897

Last Modified

2024-11-21T04:44:27.557

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System wago pfc200_firmware 03.00.39\(12\) Yes
Operating System wago pfc200_firmware 03.01.07\(13\) Yes
Operating System wago pfc200_firmware 03.02.02\(14\) Yes
Hardware wago pfc200 - No

References