CVE-2019-18202Externally Controlled Reference to a Resource in Another Sphere in PFC Firmware

Severity
5.3MEDIUMNVD
EPSS
0.6%
top 29.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateMay 24

Description

Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDwago/pfc_firmware< 03.00.35\(12\)

🔴Vulnerability Details

1
GHSA
GHSA-qmjc-jmj7-3fwx: Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control2022-05-24