Wago
Wago Pfc200 Firmware: vulnerabilidades y CVE
Wago Pfc200 Firmware tiene 40 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-3379 | Media (5.3) | 0.20% | — | 20 nov 2023 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. |
| CVE-2023-4089 | Baja (2.7) | 0.47% | — | 17 oct 2023 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file… |
| CVE-2023-1698 | Crítica (9.8) | 82% | — | 15 may 2023 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system… |
| CVE-2022-45140 | Crítica (9.8) | 1.1% | — | 27 feb 2023 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. |
| CVE-2022-45139 | Media (5.3) | 0.25% | — | 27 feb 2023 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of… |
| CVE-2022-45138 | Crítica (9.8) | 0.74% | — | 27 feb 2023 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read… |
| CVE-2022-45137 | Media (6.1) | 0.38% | — | 27 feb 2023 | The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no… |
| CVE-2022-3738 | Media (5.9) | 0.63% | — | 19 ene 2023 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to… |
| CVE-2020-6090 | Alta (7.2) | 2.1% | — | 11 jun 2020 | An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote… |
| CVE-2019-5186 | Alta (7) | 0.85% | — | 23 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this… |
| CVE-2019-5185 | Alta (7) | 0.85% | — | 23 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this… |
| CVE-2019-5184 | Alta (7.8) | 0.85% | — | 23 mar 2020 | An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially crafted XML cache file written to a specific location on the device can cause a heap pointer… |
| CVE-2019-5181 | Alta (7.8) | 0.82% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a… |
| CVE-2019-5180 | Alta (7.8) | 0.66% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to… |
| CVE-2019-5179 | Alta (7.8) | 0.66% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to… |
| CVE-2019-5178 | Alta (7.8) | 0.66% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to… |
| CVE-2019-5177 | Media (5.5) | 0.46% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). The destination buffer sp+0x440 is overflowed with… |
| CVE-2019-5176 | Media (5.5) | 0.53% | — | 12 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to… |
| CVE-2019-5171 | Alta (7.8) | 1.4% | — | 12 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send specially crafted packet at 0x1ea48 to the… |
| CVE-2019-5170 | Alta (7.8) | 1.4% | — | 12 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on… |
| CVE-2019-5169 | Alta (7.8) | 1.4% | — | 12 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on… |
| CVE-2019-5182 | Media (5.5) | 0.53% | — | 11 mar 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to… |
| CVE-2019-5175 | Alta (7.8) | 1.4% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on… |
| CVE-2019-5174 | Alta (7.8) | 1.4% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the… |
| CVE-2019-5173 | Alta (7.8) | 1.4% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on… |
| CVE-2019-5172 | Alta (7.8) | 1.3% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the… |
| CVE-2019-5168 | Alta (7.8) | 1.3% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the… |
| CVE-2019-5167 | Alta (7.8) | 1.2% | — | 11 mar 2020 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to… |
| CVE-2019-5166 | Alta (7.8) | 0.82% | — | 11 mar 2020 | An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the… |
| CVE-2019-5161 | Crítica (9.1) | 2.5% | — | 11 mar 2020 | An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud… |