📦

pfc100

Vendor: wago

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 3 Remote Access
Total CVEs 19 Total Indexed
Avg. EPSS 7.94% Exploit Prob.
Latest CVE CVE-2023-3379 Nov 20

Security Vulnerability Index

Page 2 / 2
7.5 CVSS

An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting in sensitive information disclosure.

EPSS: 2.20%
9.8 CVSS
CVE-2020-8597
Exploit Found

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

EPSS: 19.58%
9.8 CVSS

An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

EPSS: 3.32%
5.3 CVSS

Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.

EPSS: 1.79%
7.5 CVSS

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

EPSS: 3.67%