CVE-2019-12549 Information
Feb 14, 2021
cve
Description
WAGO 852-303 before FW06 852-1305 before FW06 and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://cert.vde.com/en-us/advisories/vde-2019-013 https://ics-cert.us-cert.gov/advisories/ICSA-19-164-02 https://www.wago.com/us/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: