← Back

CVE-2018-5459

nvd nist
Published: Feb 13, 2018Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.

Affected (1)

1 product
Pfc200 Firmware
Configuration A
1 vulnerable · 18 platform
Vulnerable SoftwareAffected Versions
Before 02.07.07\(10\)
Running on/withPlatform Versions
Wago
750 8202
All versions
Wago
750 8202/025 000
All versions
Wago
750 8202/025 001
All versions
Wago
750 8202/025 002
All versions
Wago
750 8202/040 001
All versions
Wago
750 8203
All versions
Wago
750 8203/025 000
All versions
Wago
750 8204
All versions
Wago
750 8204/025 000
All versions
Wago
750 8206
All versions
Wago
750 8206/025 000
All versions
Wago
750 8206/025 001
All versions
Wago
750 8207
All versions
Wago
750 8207/025 000
All versions
Wago
750 8207/025 001
All versions
Wago
750 8208
All versions
Wago
750 8208/025 000
All versions
Wago
Pfc200
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.