CVE-2018-5459
published 2018-02-13CVE-2018-5459: An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different…
PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.71%
84.2th percentile
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | pfc200_firmware | < 02.07.07\(10\) | 02.07.07\(10\) |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated TCP connections to port 2455, which is the default network port for the WAGO PFC200 CoDeSys Runtime application and the attack vector for this CVE. ↗
- →Alert on specially-crafted TCP packets sent to port 2455 that perform file system operations (read/write/delete) or attempt to manipulate PLC runtime state without prior authentication handshake. ↗
- →Public exploits are available for this vulnerability; treat any external or lateral network traffic to port 2455 on WAGO PFC200 devices as high-priority alert. ↗
- ·The vulnerable CoDeSys Runtime (versions 2.3.X and 2.4.X) exposes port 2455 by default on the network; this service requires no authentication, meaning any network-reachable host can interact with it without credentials. ↗
- ·Only WAGO PFC200 firmware versions prior to 02.07.07(10) are affected; devices running FW11 or later have the patch applied. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
WAGO PFC200 Series
cisa_ics·2017-12-07
WAGO PFC200 Series
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
WAGO PFC200 Series
Last RevisedFebruary 15, 2018
Alert CodeICSA-18-044-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit. Public exploits are available.
Vendor: WAGO
Equipment: PFC200 Series
Vulnerability: Improper Authentication
## UPDATE INFORMATION
This advisory is a follow-up to the alert titled ICS-ALERT-17-341-01 WAGO PFC200 that was published December 7, 2017, on the NCCIC/ICS-CERT website.
## AFFECTED PRODUCTS
The following 3S CoDeSys Runtime versions of the PFC200 Series are affected:
- CoDeSys Version 2.3.X
- CoDeSys Version 2.4.X
T
GHSA
GHSA-qff4-8m6q-cpvp: An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2
ghsa_unreviewed·2022-05-13
CVE-2018-5459 [CRITICAL] CWE-287 GHSA-qff4-8m6q-cpvp: An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-13
Published