QID 590953

Date Published: 2022-07-29

QID 590953: WAGO PFC200 Cloud Connectivity Remote Code Execution (RCE) Vulnerability (TALOS-2019-0954)

Tested Versions
WAGO PFC200 Firmware version 03.02.02(14) WAGO PFC200 Firmware version 03.01.07(13) WAGO PFC200 Firmware version 03.00.39(12)

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200. A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section TALOS-2019-0954 for affected packages and patching details.

    CVEs related to QID 590953

    Software Advisories
    Advisory ID Software Component Link
    TALOS-2019-0954 URL Logo talosintelligence.com/vulnerability_reports/TALOS-2019-0954