PT-2021-3332 · Wago · Wago Pfc 200

Published

2021-05-24

·

Updated

2025-08-15

·

CVE-2021-21001

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WAGO PFC200 devices (affected versions not specified)
Description The issue is related to the WAGO PFC200 devices, where an authorized attacker with network access can access the file system with higher privileges using specially crafted packets. This is due to incorrect restriction of the path name to a directory with limited access. The exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-03133
CVE-2021-21001

Affected Products

Wago Pfc 200