Back to overview

CVE-2020-12522

CRITICAL
10.0
CVSS 3.1
Description
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.

Metadata

CVE ID
CVE-2020-12522
State
PUBLISHED
Assigner
CERTVDE
Reserved
2020-04-30 00:00 UTC
Published
2020-12-17 22:40 UTC
Last updated
2024-09-16 18:14 UTC
Primary CWE
CWE-78
CWE-78 OS Command Injection
Vendor / Product
WAGO / Series PFC 100 (750-81xx/xxx-xxx)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (5)
VendorProductPlatformVersions
WAGO Series PFC 100 (750-81xx/xxx-xxx) FW1 ≤ FW10
WAGO Series PFC 200 (750-82xx/xxx-xxx) FW1 ≤ FW10
WAGO Series Wago Touch Panel 600 Advanced Line (762-5xxx) FW1 ≤ FW10
WAGO Series Wago Touch Panel 600 Marine Line (762-6xxx) FW1 ≤ FW10
WAGO Series Wago Touch Panel 600 Standard Line (762-4xxx) FW1 ≤ FW10
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 OS Command Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview