Beveiligingsadvies

CVE-2019-5156

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-03-10 23:14:34
Laatst bijgewerkt 2024-08-04 19:47:56
Toegewezen door talos
CVSS-score geen score
Status PUBLISHED

Beschrijving

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.