#VU18796 Use of hard-coded credentials in WAGO products - CVE-2019-12549
Published: June 13, 2019 / Updated: June 14, 2019
Vulnerability identifier: #VU18796
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-12549
CWE-ID: CWE-798
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
WAGO Industrial Managed Switch 852-1505
WAGO Industrial Managed Switch 852-1305
WAGO Industrial Managed Switch 852-303
WAGO Industrial Managed Switch 852-1505
WAGO Industrial Managed Switch 852-1305
WAGO Industrial Managed Switch 852-303
Software vendor:
WAGO
WAGO
Description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded SSH key that cannot be regenerated. A remote unauthenticated attacker with access to the key can compromise the affected device.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install updates from vendor's website.