Article No° | Product Name | Affected Version(s) |
---|---|---|
0852-0602 | Industrial Managed Switch | < 1.0.6.S0 |
0852-0603 | Industrial Managed Switch | < 1.0.6.S0 |
0852-1605 | Industrial Managed Switch | < 1.2.5.S0 |
Affected products are vulnerable to remote code execution via command injection in the web-based management by an attacker.
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based management.
An unprivileged attacker can fully compromise the system and access all files.
Mitigation
Remediation
WAGO recommends all affected users of products 0852-0602, 0852-0603 to update to firmware version 1.0.6.S0 and all affected users of 852-1605 to update to firmware version 1.2.5.S0.
The vulnerability was reported by INTILION AG and GAI NetConsult.
Coordination done by CERT@VDE.