CVE-2018-5459: Critical severity WAGO PFC200 Firmware vulnerability
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to Port 2455 (CoDeSys Runtime) so only trusted hosts/networks can reach it, because the CoDeSys Runtime application is network-accessible by default on Port 2455.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5459?
The severity of CVE-2018-5459 is critical with a score of 9.8 out of 10.
What is the affected software for CVE-2018-5459?
The affected software for CVE-2018-5459 includes WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X.
What is the vulnerability description of CVE-2018-5459?
CVE-2018-5459 is an Improper Authentication issue in WAGO PFC200 Series 3S CoDeSys Runtime which allows an attacker to execute unauthenticated remote operations.
What is the reference link for CVE-2018-5459?
For more information about CVE-2018-5459, you can refer to the advisory issued by the ICS-CERT.
How can I fix CVE-2018-5459?
To fix CVE-2018-5459, it is recommended to update to the latest version of WAGO PFC200 Series 3S CoDeSys Runtime.