Article No° | Product Name | Affected Version(s) |
---|---|---|
750-81xx/xxx-xxx (PFC100) | < FW12 | |
750-82xx/xxx-xxx (PFC200) | < FW12 |
The reported vulnerability allows a remote attacker to check paths and file names that are used in filesystem operations.
Update, 18.9.2019, 18:30
The vulnerability allows an attacker to check the existence of files via specially crafted HTTP requests. This can be potentially used to identify installed software and leak of sensitive data (e.g. session data stored in the file system).
Update your device to the latest firmware (>= FW 12).
Mitigation
This vulnerability was reported by Nico Jansen (Fachhochschule Aachen) to WAGO coordinated by CERT@VDE.