CVE-2016-9362: Critical severity WAGO PFC200 Firmware vulnerability
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to edit and to view settings without authenticating.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9362?
CVE-2016-9362 has been rated as high severity due to the potential for unauthorized access to sensitive configurations.
How do I fix CVE-2016-9362?
To mitigate CVE-2016-9362, update the firmware of affected WAGO devices to the latest version, specifically FW04 for the PFC200 and FW09 for the 750-881.
Which WAGO devices are affected by CVE-2016-9362?
CVE-2016-9362 affects the WAGO 750-8202/PFC200 prior to FW04, the WAGO 750-881 prior to FW09, and WAGO firmware for the 0758-0874-0000-0111.
What kind of attack is possible with CVE-2016-9362?
An attacker can exploit CVE-2016-9362 to access and modify the device settings via a specific URL on the web server.
Is CVE-2016-9362 being actively exploited in the wild?
There is currently no confirmed evidence that CVE-2016-9362 is being actively exploited in the wild, but the vulnerability should be addressed promptly.