CVE-2020-6090

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
11/06/2020
Last modified:
07/02/2023

Description

An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:pfc200_firmware:03.03.10\(15\):*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools