Use of hard-coded credentials in WAGO products - CVE-2019-12549
Published: June 13, 2019 / Updated: June 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded SSH key that cannot be regenerated. A remote unauthenticated attacker with access to the key can compromise the affected device.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
WAGO Industrial Managed Switch 852-1305
WAGO Industrial Managed Switch 852-303
How to mitigate CVE-2019-12549
WAGO Industrial Managed Switch 852-1305 - update to 1.1.6.S0
WAGO Industrial Managed Switch 852-303 - update to 1.2.2.S0