- Description
- An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.
- Source
- talos-cna@cisco.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 9
- Impact score
- 10
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:C/I:C/A:C
- nvd@nist.gov
- CWE-345
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:pfc200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "634EB95B-254B-4310-9192-5EE98F915CC7"
},
{
"criteria": "cpe:2.3:o:wago:pfc200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDEB63D9-EE1C-4005-B04C-7C9BBD746402"
},
{
"criteria": "cpe:2.3:o:wago:pfc200_firmware:03.02.02\\(14\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6274B67D-C65B-4834-9DB5-6FB3D0ADD3A9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "688A3248-7EAA-499D-A47C-A4D4900CDBD1"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]