PT-2020-11095 · Wago · Wago Pfc 200
Published
2020-03-11
·
Updated
2020-03-17
·
CVE-2019-5176
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
WAGO PFC 200 Firmware version 03.02.02(14)
Description
A stack buffer overflow issue exists in the iocheckd service, specifically in the 'I/O-Check' functionality. This can be triggered by sending a specially crafted packet, causing the parsing of a cache file. The
sprintf() function overflows the destination buffer sp+0x40 when the gateway value exceeds a certain length. A gateway value of length 0x7e2 can cause the service to crash.Recommendations
For WAGO PFC 200 Firmware version 03.02.02(14), consider restricting the length of gateway values to prevent the overflow, or avoid using the
sprintf() function for gateway values until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago Pfc 200