CVE-2019-5156
Summary
| CVE | CVE-2019-5156 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-11 22:27:00 UTC |
| Updated | 2020-03-18 17:51:00 UTC |
| Description | An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| TALOS-2019-0949 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence |
MISC |
talosintelligence.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590951 WAGO PFC200 Cloud Connectivity TimeoutPrepared Command Injection Vulnerability (TALOS-2019-0949)