#VU26261 Improper access control in Wago PFC200 Controller - CVE-2019-5160
Published: March 20, 2020
Wago PFC200 Controller
WAGO
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Cloud Connectivity functionality. A remote administrator can use a specially crafted HTTPS POST request, bypass implemented security restrictions and gain unauthorized access to firmware update functionality.