CVE-2019-12550

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
17/06/2019
Last modified:
19/06/2019

Description

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:852-303_firmware:*:*:*:*:*:*:*:* 1.2.2.s0 (excluding)
cpe:2.3:h:wago:852-303:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:852-1305_firmware:*:*:*:*:*:*:*:* 1.1.6.s0 (excluding)
cpe:2.3:h:wago:852-1305:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:852-1505_firmware:*:*:*:*:*:*:*:* 1.1.5.s0 (excluding)
cpe:2.3:h:wago:852-1505:-:*:*:*:*:*:*:*