Wago Pfc200 Firmware vulnerabilities
39 known vulnerabilities affecting wago/pfc200_firmware.
Total CVEs
39
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH23MEDIUM8LOW1
Vulnerabilities
Page 1 of 2
CVE-2023-1698P1CRITICALCVSS 9.8ExploitedPoC≥ 20, ≤ 232023-05-15
CVE-2023-1698 [CRITICAL] CWE-78 CVE-2023-1698: In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create ne
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
nvd
CVE-2022-45140P2CRITICALCVSS 9.8≥ 16, < 22v22+1 more2023-02-27
CVE-2022-45140 [CRITICAL] CWE-306 CVE-2022-45140: The configuration backend allows an unauthenticated user to write arbitrary data with root privilege
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
nvd
CVE-2018-5459P2CRITICALCVSS 9.8fixed in 02.07.07\(10\)2018-02-13
CVE-2018-5459 [CRITICAL] CWE-287 CVE-2018-5459: An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as read
nvd
CVE-2022-45138P2CRITICALCVSS 9.8≥ 16, < 22v22+1 more2023-02-27
CVE-2022-45138 [CRITICAL] CWE-306 CVE-2022-45138: The configuration backend of the web-based management can be used by unauthenticated users, although
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
nvd
CVE-2019-5082P3CRITICALCVSS 9.8v03.00.39\(12\)v03.01.07\(13\)2020-01-08
CVE-2019-5082 [CRITICAL] CWE-787 CVE-2019-5082: An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functiona
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution.
nvd
CVE-2019-5160P3CRITICALCVSS 9.1v03.00.39\(12\)v03.01.07\(13\)+1 more2020-03-11
CVE-2019-5160 [CRITICAL] CVE-2019-5160: An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality
An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker ca
nvd
CVE-2019-5161P3CRITICALCVSS 9.1v03.00.39\(12\)v03.01.07\(13\)+1 more2020-03-11
CVE-2019-5161 [CRITICAL] CWE-345 CVE-2019-5161: An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.
nvd
CVE-2019-5155P3HIGHCVSS 7.2v03.00.39\(12\)v03.01.07\(13\)+1 more2020-03-11
CVE-2019-5155 [HIGH] CWE-78 CVE-2019-5155: An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC2
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)
nvd
CVE-2019-5157P3HIGHCVSS 7.2v03.00.39\(12\)v03.01.07\(13\)+1 more2020-03-11
CVE-2019-5157 [HIGH] CWE-78 CVE-2019-5157: An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAG
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.
nvd
CVE-2019-5156P3HIGHCVSS 7.2v03.00.39\(12\)v03.01.07\(13\)+1 more2020-03-11
CVE-2019-5156 [HIGH] CWE-78 CVE-2019-5156: An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAG
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.
nvd
CVE-2019-5134P3HIGHCVSS 7.5v03.00.39\(12\)v03.01.07\(13\)2020-03-11
CVE-2019-5134 [HIGH] CVE-2019-5134: An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (
An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting in sensitive information disclosure.
nvd
CVE-2020-6090P3HIGHCVSS 7.2v03.03.10\(15\)2020-06-11
CVE-2020-6090 [HIGH] CWE-345 CVE-2020-6090: An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality o
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2019-5170P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-12
CVE-2019-5170 [HIGH] CWE-78 CVE-2019-5170: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.A
nvd
CVE-2019-5175P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-11
CVE-2019-5175 [HIGH] CWE-78 CVE-2019-5175: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.A
nvd
CVE-2019-5174P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-11
CVE-2019-5174 [HIGH] CWE-78 CVE-2019-5174: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e9fc
nvd
CVE-2019-5173P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-11
CVE-2019-5173 [HIGH] CWE-78 CVE-2019-5173: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.
nvd
CVE-2019-5171P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-12
CVE-2019-5171 [HIGH] CWE-78 CVE-2019-5171: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send specially crafted packet at 0x1ea48 to the extracted hostname value from the xml file that is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=enabled ip-ad
nvd
CVE-2019-5169P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-12
CVE-2019-5169 [HIGH] CWE-78 CVE-2019-5169: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.
nvd
CVE-2019-5172P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-11
CVE-2019-5172 [HIGH] CWE-78 CVE-2019-5172: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e840 the extracted ntp value from the xml file is used as an argument to /etc/config-tools/config_sntp time-s
nvd
CVE-2019-5167P3HIGHCVSS 7.8v03.02.02\(14\)2020-03-11
CVE-2019-5167 [HIGH] CWE-78 CVE-2019-5167: An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d dns-server-name= using sprintf(). This command is later executed via a call to sys
nvd
1 / 2Next →