CVE-2019-12549
17.06.2019, 17:15
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.Enginsight
Vendor | Product | Version |
---|---|---|
wago | 852-303_firmware | 𝑥 < 1.2.2.s0 |
wago | 852-1305_firmware | 𝑥 < 1.1.6.s0 |
wago | 852-1505_firmware | 𝑥 < 1.1.5.s0 |
𝑥
= Vulnerable software versions