Skip to main content

Vendor/product archive

wago / pfc100 CVEs

Beta · best-effort

15 CVEs tagged to wago / pfc1005 Critical, 3 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2023-1698

Published May 15, 2023

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended beha…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-45140

Published Feb 27, 2023

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-45138

Published Feb 27, 2023

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allo…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-3738

Published Jan 19, 2023

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryp…

CVSS 5.9 · Medium

CVE-2019-18202

Published Oct 19, 2019

Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1