CVE-2019-18202 — Externally Controlled Reference to a Resource in Another Sphere in PFC Firmware
Severity
5.3MEDIUMNVD
EPSS
0.6%
top 29.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateMay 24
Description
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages1 packages
🔴Vulnerability Details
1GHSA▶
GHSA-qmjc-jmj7-3fwx: Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control↗2022-05-24