Learn about CVE-2019-18202 affecting WAGO Series PFC100 and PFC200 devices. Discover the impact, technical details, and mitigation steps for this information disclosure vulnerability.
WAGO Series PFC100 and PFC200 devices before firmware version 12 are vulnerable to information disclosure due to improper access control.
Understanding CVE-2019-18202
Before firmware version 12, a security vulnerability exists in WAGO Series PFC100 and PFC200 devices that could lead to potential information disclosure.
What is CVE-2019-18202?
This CVE describes the issue of improper access control on WAGO Series PFC100 and PFC200 devices, allowing remote attackers to potentially disclose information by sending crafted HTTP requests.
The Impact of CVE-2019-18202
Technical Details of CVE-2019-18202
WAGO Series PFC100 and PFC200 devices are affected by the following:
Vulnerability Description
The vulnerability allows remote attackers to verify the presence of paths and file names through specially crafted HTTP requests.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by sending malicious HTTP requests to the affected devices, enabling attackers to confirm the existence of specific paths and files.
Mitigation and Prevention
It is crucial to take immediate steps to address and prevent potential exploitation of CVE-2019-18202:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates