Description
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A single packet can cause a denial of service and weaken credentials resulting in the default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0872
Scores
CVSS v3
9.1
EPSS
0.0160
EPSS Percentile
72.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (3)
wago/pfc_100_firmware
03.00.39\(12\)
wago/pfc_200_firmware
03.00.39\(12\)
wago/pfc_200_firmware
03.01.07\(13\)
Published
Dec 18, 2019
Tracked Since
Feb 18, 2026