CVE-2019-12550
WAGO 852 Industrial Managed Switch Series Code Execution / Hardcoded Credentials
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
WAGO 852-303 anterior de FW06, 852-1305 anterior de FW06 y 852-1505 antes de que los dispositivos FW03 contengan usuarios codificados y contraseñas que se pueden usar para iniciar sesión a través de SSH y TELNET
The industrial managed switch series 852 from WAGO is affected by multiple vulnerabilities such as old software components embedded in the firmware. Furthermore, hardcoded password hashes and credentials were also found by doing an automated scan with IoT Inspector.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-06-02 CVE Reserved
- 2019-06-13 CVE Published
- 2024-08-04 CVE Updated
- 2024-11-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en-us/advisories/vde-2019-013 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-19-164-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.wago.com/us | 2019-06-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wago Search vendor "Wago" | 852-303 Firmware Search vendor "Wago" for product "852-303 Firmware" | < 1.2.2.s0 Search vendor "Wago" for product "852-303 Firmware" and version " < 1.2.2.s0" | - |
Affected
| in | Wago Search vendor "Wago" | 852-303 Search vendor "Wago" for product "852-303" | - | - |
Safe
|
Wago Search vendor "Wago" | 852-1305 Firmware Search vendor "Wago" for product "852-1305 Firmware" | < 1.1.6.s0 Search vendor "Wago" for product "852-1305 Firmware" and version " < 1.1.6.s0" | - |
Affected
| in | Wago Search vendor "Wago" | 852-1305 Search vendor "Wago" for product "852-1305" | - | - |
Safe
|
Wago Search vendor "Wago" | 852-1505 Firmware Search vendor "Wago" for product "852-1505 Firmware" | < 1.1.5.s0 Search vendor "Wago" for product "852-1505 Firmware" and version " < 1.1.5.s0" | - |
Affected
| in | Wago Search vendor "Wago" | 852-1505 Search vendor "Wago" for product "852-1505" | - | - |
Safe
|