PT-2020-13155 · Wago · Wago Series Pfc 200+4
Florian Seidel
+1
·
Published
2020-12-17
·
Updated
2020-12-23
·
CVE-2020-12522
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WAGO Series PFC 100 versions 750-81xx/xxx-xxx with firmware versions <=FW10
WAGO Series PFC 200 versions 750-82xx/xxx-xxx with firmware versions <=FW10
WAGO Series Wago Touch Panel 600 Standard Line versions 762-4xxx with firmware versions <=FW10
WAGO Series Wago Touch Panel 600 Advanced Line versions 762-5xxx with firmware versions <=FW10
WAGO Series Wago Touch Panel 600 Marine Line versions 762-6xxx with firmware versions <=FW10
Description
The reported issue allows an attacker with network access to the device to execute code using specially crafted packets. This can be done in various WAGO series devices.
Recommendations
For WAGO Series PFC 100 versions 750-81xx/xxx-xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.
For WAGO Series PFC 200 versions 750-82xx/xxx-xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.
For WAGO Series Wago Touch Panel 600 Standard Line versions 762-4xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.
For WAGO Series Wago Touch Panel 600 Advanced Line versions 762-5xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.
For WAGO Series Wago Touch Panel 600 Marine Line versions 762-6xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago Series Pfc 100
Wago Series Pfc 200
Wago Series Wago Touch Panel 600 Advanced Line
Wago Series Wago Touch Panel 600 Marine Line
Wago Series Wago Touch Panel 600 Standard Line