// For flags

CVE-2019-12550

WAGO 852 Industrial Managed Switch Series Code Execution / Hardcoded Credentials

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

WAGO 852-303 anterior de FW06, 852-1305 anterior de FW06 y 852-1505 antes de que los dispositivos FW03 contengan usuarios codificados y contraseñas que se pueden usar para iniciar sesión a través de SSH y TELNET

The industrial managed switch series 852 from WAGO is affected by multiple vulnerabilities such as old software components embedded in the firmware. Furthermore, hardcoded password hashes and credentials were also found by doing an automated scan with IoT Inspector.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-06-02 CVE Reserved
  • 2019-06-13 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-11-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Wago
Search vendor "Wago"
852-303 Firmware
Search vendor "Wago" for product "852-303 Firmware"
< 1.2.2.s0
Search vendor "Wago" for product "852-303 Firmware" and version " < 1.2.2.s0"
-
Affected
in Wago
Search vendor "Wago"
852-303
Search vendor "Wago" for product "852-303"
--
Safe
Wago
Search vendor "Wago"
852-1305 Firmware
Search vendor "Wago" for product "852-1305 Firmware"
< 1.1.6.s0
Search vendor "Wago" for product "852-1305 Firmware" and version " < 1.1.6.s0"
-
Affected
in Wago
Search vendor "Wago"
852-1305
Search vendor "Wago" for product "852-1305"
--
Safe
Wago
Search vendor "Wago"
852-1505 Firmware
Search vendor "Wago" for product "852-1505 Firmware"
< 1.1.5.s0
Search vendor "Wago" for product "852-1505 Firmware" and version " < 1.1.5.s0"
-
Affected
in Wago
Search vendor "Wago"
852-1505
Search vendor "Wago" for product "852-1505"
--
Safe