Vulnerability Description
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wago | Pfc200 Firmware | 03.03.10\(15\) |
| Wago | Pfc200 | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1010Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1010Third Party Advisory
FAQ
What is CVE-2020-6090?
CVE-2020-6090 is a vulnerability with a CVSS score of 7.2 (HIGH). An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution re...
How severe is CVE-2020-6090?
CVE-2020-6090 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6090?
Check the references section above for vendor advisories and patch information. Affected products include: Wago Pfc200 Firmware, Wago Pfc200.