An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wago
Subscribe
|
750-8202
Subscribe
750-8202\/025-000
Subscribe
750-8202\/025-001
Subscribe
750-8202\/025-002
Subscribe
750-8202\/040-001
Subscribe
750-8203
Subscribe
750-8203\/025-000
Subscribe
750-8204
Subscribe
750-8204\/025-000
Subscribe
750-8206
Subscribe
750-8206\/025-000
Subscribe
750-8206\/025-001
Subscribe
750-8207
Subscribe
750-8207\/025-000
Subscribe
750-8207\/025-001
Subscribe
750-8208
Subscribe
750-8208\/025-000
Subscribe
Pfc200
Subscribe
Pfc200 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17229 | An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-18-044-01 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T05:33:44.375Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5459
No data.
Status : Modified
Published: 2018-02-13T21:29:00.207
Modified: 2024-11-21T04:08:50.547
Link: CVE-2018-5459
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD