An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.
2020-03-11T22:27:41.160
2024-11-21T04:44:28.010
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | wago | pfc200_firmware | 03.00.39\(12\) | Yes |
Operating System | wago | pfc200_firmware | 03.01.07\(13\) | Yes |
Operating System | wago | pfc200_firmware | 03.02.02\(14\) | Yes |
Hardware | wago | pfc200 | - | No |