CVE-2019-5157: Command Injection
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5157?
CVE-2019-5157 is a command injection vulnerability in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12).
How severe is CVE-2019-5157?
CVE-2019-5157 has a severity rating of 7.2 (High).
How can an attacker exploit CVE-2019-5157?
An attacker can inject OS commands into the TimeoutUnconfirmed parameter value in the Firmware Update command.
Which versions of WAGO PFC200 Firmware are affected by CVE-2019-5157?
WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12) are affected by CVE-2019-5157.
Is WAGO PFC200 itself vulnerable to CVE-2019-5157?
No, WAGO PFC200 itself is not vulnerable to CVE-2019-5157.