CVE-2019-18202

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2019
Last modified:
13/03/2023

Description

Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:pfc_firmware:*:*:*:*:*:*:*:* 03.00.35\(12\) (excluding)
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools