Learn about CVE-2019-5169, a command injection vulnerability in WAGO PFC200 Firmware version 03.02.02(14) allowing unauthorized OS command execution. Find mitigation steps here.
A vulnerability in the iocheckd service's "I/O-Check" function of the WAGO PFC 200 Firmware version 03.02.02(14) allows for command injection, potentially leading to unauthorized execution of operating system commands.
Understanding CVE-2019-5169
This CVE involves a command injection vulnerability in a specific firmware version of the WAGO PFC 200, which can be exploited through a crafted XML cache file.
What is CVE-2019-5169?
The vulnerability in the iocheckd service of the WAGO PFC 200 Firmware version 03.02.02(14) enables attackers to inject operating system commands by manipulating a custom XML cache file.
The Impact of CVE-2019-5169
Exploiting this vulnerability could result in unauthorized execution of commands on the affected device, potentially leading to further compromise or disruption.
Technical Details of CVE-2019-5169
This section provides more in-depth technical insights into the vulnerability.
Vulnerability Description
The vulnerability allows for command injection through the parsing of a specially crafted XML cache file, leading to the execution of unauthorized operating system commands.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
To address and prevent the exploitation of CVE-2019-5169, the following steps are recommended:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates