Use of hard-coded credentials in WAGO products - CVE-2019-12549

 

Use of hard-coded credentials in WAGO products - CVE-2019-12549

Published: June 13, 2019 / Updated: June 14, 2019


Vulnerability identifier: #VU18796
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12549
CWE-ID: CWE-798
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded SSH key that cannot be regenerated. A remote unauthenticated attacker with access to the key can compromise the affected device.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

WAGO Industrial Managed Switch 852-1505
WAGO Industrial Managed Switch 852-1305
WAGO Industrial Managed Switch 852-303

How to mitigate CVE-2019-12549

Install updates from vendor's website.

WAGO Industrial Managed Switch 852-1505 - update to 1.1.5.S0
WAGO Industrial Managed Switch 852-1305 - update to 1.1.6.S0
WAGO Industrial Managed Switch 852-303 - update to 1.2.2.S0

External References

Related Security Bulletins