PT-2020-13155 · Wago · Wago Series Pfc 200+4

Florian Seidel

+1

·

Published

2020-12-17

·

Updated

2020-12-23

·

CVE-2020-12522

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WAGO Series PFC 100 versions 750-81xx/xxx-xxx with firmware versions <=FW10 WAGO Series PFC 200 versions 750-82xx/xxx-xxx with firmware versions <=FW10 WAGO Series Wago Touch Panel 600 Standard Line versions 762-4xxx with firmware versions <=FW10 WAGO Series Wago Touch Panel 600 Advanced Line versions 762-5xxx with firmware versions <=FW10 WAGO Series Wago Touch Panel 600 Marine Line versions 762-6xxx with firmware versions <=FW10
Description The reported issue allows an attacker with network access to the device to execute code using specially crafted packets. This can be done in various WAGO series devices.
Recommendations For WAGO Series PFC 100 versions 750-81xx/xxx-xxx with firmware versions <=FW10, update the firmware to a version higher than FW10. For WAGO Series PFC 200 versions 750-82xx/xxx-xxx with firmware versions <=FW10, update the firmware to a version higher than FW10. For WAGO Series Wago Touch Panel 600 Standard Line versions 762-4xxx with firmware versions <=FW10, update the firmware to a version higher than FW10. For WAGO Series Wago Touch Panel 600 Advanced Line versions 762-5xxx with firmware versions <=FW10, update the firmware to a version higher than FW10. For WAGO Series Wago Touch Panel 600 Marine Line versions 762-6xxx with firmware versions <=FW10, update the firmware to a version higher than FW10.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12522

Affected Products

Wago Series Pfc 100
Wago Series Pfc 200
Wago Series Wago Touch Panel 600 Advanced Line
Wago Series Wago Touch Panel 600 Marine Line
Wago Series Wago Touch Panel 600 Standard Line