PT-2020-11083 · Wago · Wago Pfc 200

Published

2020-03-10

·

Updated

2021-07-21

·

CVE-2019-5160

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12)
Description An improper host validation issue exists in the Cloud Connectivity functionality, allowing a specially crafted HTTPS POST request to cause the software to connect to an unauthorized host. This results in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker-controlled Azure IoT Hub node.
Recommendations For version 03.02.02(14), update to a version that fixes the improper host validation issue. For version 03.01.07(13), update to a version that fixes the improper host validation issue. For version 03.00.39(12), update to a version that fixes the improper host validation issue. As a temporary workaround, consider restricting access to the Cloud Connectivity functionality until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-5160

Affected Products

Wago Pfc 200