threat
engine
.sh
Back
·
··:··
Home
/
Product
/
wago pfc100 firmware
Product
wago pfc100 firmware
22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-3379
< 22
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the pas
5.3
MEDIUM
CVE-2023-4089
>= 16 and <= 26
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to thr
2.7
LOW
CVE-2023-1698
>= 20 and <= 23
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device
9.8
CRITICAL
CVE-2022-45140
>= 16 and < 22
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could
9.8
CRITICAL
CVE-2022-45139
>= 16 and < 22
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages
5.3
MEDIUM
CVE-2022-45138
>= 16 and < 22
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users shou
9.8
CRITICAL
CVE-2022-45137
>= 16 and < 22
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets t
6.1
MEDIUM
CVE-2022-3738
>= 16 and <= 22
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contai
5.9
MEDIUM
CVE-2020-12522
<= 10
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets
10.0
CRITICAL
CVE-2019-5149
all versions
The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lightt
7.5
HIGH
CVE-2019-5135
all versions
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web a
5.3
MEDIUM
CVE-2019-5134
all versions
An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functional
7.5
HIGH
CVE-2019-5082
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware v
9.8
CRITICAL
CVE-2019-5080
all versions
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware v
9.1
CRITICAL
CVE-2019-5079
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware
9.8
CRITICAL
CVE-2019-5078
all versions
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware ve
9.1
CRITICAL
CVE-2019-5075
all versions
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware ve
9.8
CRITICAL
CVE-2019-5073
all versions
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware
5.3
MEDIUM
CVE-2019-5081
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmwa
9.8
CRITICAL
CVE-2019-5077
all versions
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 F
9.1
CRITICAL
CVE-2019-5074
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmw
9.8
CRITICAL
CVE-2019-10953
all versions
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have foun
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin