threat
engine
.sh
Back
·
··:··
Home
/
Product
/
wago pfc200 firmware
Product
wago pfc200 firmware
49 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-3379
< 22
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the pas
5.3
MEDIUM
CVE-2023-4089
>= 16 and <= 26
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to thr
2.7
LOW
CVE-2023-1698
>= 20 and <= 23
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device
9.8
CRITICAL
CVE-2022-45140
>= 16 and < 22
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could
9.8
CRITICAL
CVE-2022-45139
>= 16 and < 22
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages
5.3
MEDIUM
CVE-2022-45138
>= 16 and < 22
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users shou
9.8
CRITICAL
CVE-2022-45137
>= 16 and < 22
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets t
6.1
MEDIUM
CVE-2022-3738
>= 16 and <= 22
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contai
5.9
MEDIUM
CVE-2020-12522
<= 10
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets
10.0
CRITICAL
CVE-2020-6090
all versions
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A
7.2
HIGH
CVE-2019-5186
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO
7.0
HIGH
CVE-2019-5185
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO
7.0
HIGH
CVE-2019-5184
all versions
An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially cra
7.8
HIGH
CVE-2019-5181
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
7.8
HIGH
CVE-2019-5180
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
7.8
HIGH
CVE-2019-5179
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
7.8
HIGH
CVE-2019-5178
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
7.8
HIGH
CVE-2019-5177
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
5.5
MEDIUM
CVE-2019-5176
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
5.5
MEDIUM
CVE-2019-5171
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5170
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5169
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5182
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of W
5.5
MEDIUM
CVE-2019-5175
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5174
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version
7.8
HIGH
CVE-2019-5173
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5172
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmwar
7.8
HIGH
CVE-2019-5168
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version
7.8
HIGH
CVE-2019-5167
all versions
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version
7.8
HIGH
CVE-2019-5166
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 ve
7.8
HIGH
CVE-2019-5161
all versions
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02
9.1
CRITICAL
CVE-2019-5160
all versions
An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versi
9.1
CRITICAL
CVE-2019-5157
all versions
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.
7.2
HIGH
CVE-2019-5156
all versions
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14)
7.2
HIGH
CVE-2019-5155
all versions
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject ope
7.2
HIGH
CVE-2019-5149
all versions
The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lightt
7.5
HIGH
CVE-2019-5135
all versions
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web a
5.3
MEDIUM
CVE-2019-5134
all versions
An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functional
7.5
HIGH
CVE-2019-5082
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware v
9.8
CRITICAL
CVE-2019-5080
all versions
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware v
9.1
CRITICAL
CVE-2019-5079
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware
9.8
CRITICAL
CVE-2019-5078
all versions
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware ve
9.1
CRITICAL
CVE-2019-5075
all versions
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware ve
9.8
CRITICAL
CVE-2019-5073
all versions
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware
5.3
MEDIUM
CVE-2019-5081
all versions
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmwa
9.8
CRITICAL
CVE-2019-5077
all versions
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 F
9.1
CRITICAL
CVE-2019-5074
all versions
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmw
9.8
CRITICAL
CVE-2018-5459
< 02.07.07\(10\)
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can
9.8
CRITICAL
CVE-2016-9362
all versions
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August
9.1
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin