Wago

Pfc200 Firmware

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.47%
  • Veröffentlicht 11.03.2020 22:27:41
  • Zuletzt bearbeitet 21.11.2024 04:44:28

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the extracted domainname value from the xm...

Exploit
  • EPSS 2.86%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:27

An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter valu...

Exploit
  • EPSS 2.86%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:27

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter va...

Exploit
  • EPSS 2.46%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:27

An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC2...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:26

The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applic...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:25

An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploi...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 11.03.2020 22:27:40
  • Zuletzt bearbeitet 21.11.2024 04:44:24

An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted aut...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 08.01.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:18

An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A special...

  • EPSS 0.91%
  • Veröffentlicht 13.02.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:50

An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via ...

  • EPSS 0.21%
  • Veröffentlicht 13.02.2017 21:59:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicio...