An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-044-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2018-02-13T21:00:00
Updated: 2024-08-05T05:33:44.375Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5459
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-02-13T21:29:00.207
Modified: 2024-11-21T04:08:50.547
Link: CVE-2018-5459
Redhat
No data.