CVE-2019-5082: Buffer Overflow
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5082?
CVE-2019-5082 is an exploitable heap buffer overflow vulnerability in the iocheckd service I/O-Check functionality of WAGO PFC200 and PFC100 firmware.
What is the severity of CVE-2019-5082?
The severity of CVE-2019-5082 is critical, with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-5082?
WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12) are affected by CVE-2019-5082.
How does the vulnerability in CVE-2019-5082 occur?
The vulnerability in CVE-2019-5082 occurs when a specially crafted set of packets is processed by the iocheckd service, causing a heap buffer overflow.
Is WAGO PFC200 and PFC100 firmware vulnerable to CVE-2019-5082?
Yes, WAGO PFC200 and PFC100 firmware versions mentioned earlier are vulnerable to CVE-2019-5082.