PT-2020-11083 · Wago · Wago Pfc 200
Published
2020-03-10
·
Updated
2021-07-21
·
CVE-2019-5160
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12)
Description
An improper host validation issue exists in the Cloud Connectivity functionality, allowing a specially crafted HTTPS POST request to cause the software to connect to an unauthorized host. This results in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker-controlled Azure IoT Hub node.
Recommendations
For version 03.02.02(14), update to a version that fixes the improper host validation issue.
For version 03.01.07(13), update to a version that fixes the improper host validation issue.
For version 03.00.39(12), update to a version that fixes the improper host validation issue.
As a temporary workaround, consider restricting access to the Cloud Connectivity functionality until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wago Pfc 200