QID 590735
QID 590735: WAGO MandM Software fdtCONTAINER (Update C) Vulnerability (ICSA-21-021-05)
AFFECTED PRODUCTS
The following products are affected:
fdtCONTAINER component
Versions between 3.5.0 and 3.5.20304.x
Versions between 3.6.0 and 3.6.20304.x
Versions older than 3.5
If an attacker can socially engineer a valid user into loading a manipulated project file, malicious code can be executed without notice.
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-021-05 for affected packages and patching details.
fdtCONTAINER applicationWorkaround:
dtmINSPECTOR Version 3 (Based on FDT 1.2.x)
There are reports indicating the following products incorporate the affected component:
Emerson Rosemount Transmitter Interface Software (RTIS) SKUs: 04088-9000-0001, 4088-9000-0002, and 7000003-312
PEPPERL+FUCHS PACTware 5.0, up to and including Version 5.0.5.31
Weidmller WI Manager up to and including Version 2.5.1
Mitsubishi Electric MELSOFT FieldDeviceConfigurator, Versions 1.05 F and prior
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
- ICSA-21-021-05 -
www.us-cert.gov/ics/advisories/ICSA-21-021-05
CVEs related to QID 590735
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-021-05 |
|