CVE-2019-12550: Critical severity wago 852-303 vulnerability
Published Jun 17, 2019
·Updated
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
Affected Software
6 affected components
WAGO 852-303 Firmware<1.2.2.s0
WAGO 852-303
WAGO 852-1305 Firmware<1.1.6.s0
WAGO 852-1305
WAGO 852-1505 Firmware<1.1.5.s0
WAGO 852-1505
Event History
Jun 17, 2019
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12550?
CVE-2019-12550 has a high severity due to the presence of hardcoded credentials that can be exploited to gain unauthorized access.
2
How do I fix CVE-2019-12550?
To fix CVE-2019-12550, update your WAGO device firmware to the latest version that removes the hardcoded users and passwords.
3
Which devices are affected by CVE-2019-12550?
CVE-2019-12550 affects WAGO 852-303, 852-1305, and 852-1505 devices before specific firmware versions.
4
Can CVE-2019-12550 be exploited remotely?
Yes, CVE-2019-12550 can be exploited remotely via SSH and TELNET due to the hardcoded credentials.
5
What are the potential impacts of CVE-2019-12550?
The potential impacts include unauthorized access to the devices, leading to possible manipulation or disruption of operations.