CVE-2018-12980: Malicious File Upload
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12980?
CVE-2018-12980 is considered a medium severity vulnerability allowing authenticated users to upload arbitrary files.
How do I fix CVE-2018-12980?
To fix CVE-2018-12980, update the firmware of your WAGO e!DISPLAY device to version 02 or later.
Who is affected by CVE-2018-12980?
CVE-2018-12980 affects WAGO e!DISPLAY models 762-3000 through 762-3003 running firmware versions earlier than 02.
What is the impact of CVE-2018-12980?
The impact of CVE-2018-12980 allows authenticated users to potentially compromise the system by uploading unauthorized files.
Is CVE-2018-12980 a remote vulnerability?
CVE-2018-12980 is not a remote vulnerability as it requires authentication to exploit.