ZeroHour

CVE-2019-12549

CVSS 3.0
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.

Vendors
wago
Products
852-303 firmware, 852-1305 firmware, 852-1505 firmware
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.