Vulnerabilities > CVE-2019-5159 - Exposure of Resource to Wrong Sphere vulnerability in Wago E!Cockpit 1.6.0.7

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
wago
CWE-668

Summary

An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update, potentially resulting in code execution. An attacker can create a malicious firmware update package file using any zip utility. The user must initiate a firmware update through e!COCKPIT and choose the malicious wup file using the file browser to trigger the vulnerability.

Vulnerable Configurations

Part Description Count
Application
Wago
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0952
last seen2020-03-18
published2020-03-09
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0952
titleWAGO e!COCKPIT file path improper input validation vulnerability