Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wh8-v3px-8552

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

EPSS

Процентиль: 86%
0.02855
Низкий

Связанные уязвимости

CVSS3: 7.2
nvd
почти 6 лет назад

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

EPSS

Процентиль: 86%
0.02855
Низкий