CVE-2018-5459
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Affected (1)
Products: Wago: Pfc200 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 02.07.07\(10\) |
| Running on/with | Platform Versions |
|---|---|
Wago 750 8202 | All versions |
Wago 750 8202/025 000 | All versions |
Wago 750 8202/025 001 | All versions |
Wago 750 8202/025 002 | All versions |
Wago 750 8202/040 001 | All versions |
Wago 750 8203 | All versions |
Wago 750 8203/025 000 | All versions |
Wago 750 8204 | All versions |
Wago 750 8204/025 000 | All versions |
Wago 750 8206 | All versions |
Wago 750 8206/025 000 | All versions |
Wago 750 8206/025 001 | All versions |
Wago 750 8207 | All versions |
Wago 750 8207/025 000 | All versions |
Wago 750 8207/025 001 | All versions |
Wago 750 8208 | All versions |
Wago 750 8208/025 000 | All versions |
Wago Pfc200 | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.