VendorsWAGOpfc200_firmwareany version
Vulnerabilities

WAGO PFC200 Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-1698
WAGO: WBM Command Injection in multiple products
Published 2023-05-15 · Modified
9.8EPSS 0.820
CVE-2018-5459
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Published 2018-02-13 · Modified
9.8EPSS 0.027
CVE-2022-45140
WAGO: Missing Authentication for Critical Function
Published 2023-02-27 · Modified
9.8EPSS 0.011
CVE-2022-45138
WAGO: Missing Authentication for Critical Function
Published 2023-02-27 · Modified
9.8EPSS 0.007
CVE-2016-9362
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to edit and to view settings without authenticating.
Published 2017-02-13 · Modified
9.1EPSS 0.021
CVE-2022-45137
WAGO: Reflective Cross-Site Scripting
Published 2023-02-27 · Modified
6.1EPSS 0.004
CVE-2022-3738
WAGO: Missing authentication for config export functionality in multiple products
Published 2023-01-19 · Modified
5.9EPSS 0.006
CVE-2022-45139
WAGO: Origin validation error through CORS misconfiguration
Published 2023-02-27 · Modified
5.3EPSS 0.003
CVE-2023-3379
WAGO: Improper Privilege Management in web-based management
Published 2023-11-20 · Modified
5.3EPSS 0.002
CVE-2023-4089
WAGO: Multiple products vulnerable to local file inclusion
Published 2023-10-17 · Modified
2.7EPSS 0.005