← voltar
CVE-2018-5459

CVE-2018-5459

EPSS 2.7%CWE-287
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 2.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 fev 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Produtos afetados
n/a · WAGO PFC200 Series

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →