← Back to CVE List
Vulnerability Intelligence Report
Command Injection Vulnerability in I/O-Check Service of WAGO PFC100, PFC200 and Touch Panel 600 Series with firmware versions <=FW10

CVE-2020-12522

The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:2.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.927%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT@VDE · CERT · Germany
Reserved2020-04-30T00:00:00
Published2020-12-17T22:40:48
Patch Date2020-12-17
Last Updated2024-09-16T18:14:32

LINK COPIED TO CLIPBOARD