CVE-2019-12549
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.
Affected (3)
Products: Wago: 852 303 Firmware, 852 1305 Firmware, 852 1505 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.2.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 852 303 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.6.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 852 1305 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.5.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 852 1505 | All versions |
References (6)
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.