CVE-2020-6090
Last modified
CVE-2020-6090 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. EPSS estimates a 2.06% chance of exploitation in the next 30 days.
Description
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wago | Pfc200 Firmware | 03.03.10\(15\) |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1010Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1010Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6090?
How severe is CVE-2020-6090?
How do I fix CVE-2020-6090?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-6084An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6085An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6086An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6087An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6088An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6089An exploitable code execution vulnerability exists in the AN…7.8
- CVE-2020-6091An exploitable authentication bypass vulnerability exists in…9.1
- CVE-2020-6092An exploitable code execution vulnerability exists in the wa…7.8
- CVE-2020-6093An exploitable information disclosure vulnerability exists i…5.5
- CVE-2020-6094An exploitable code execution vulnerability exists in the TI…8.8
- CVE-2020-6095An exploitable denial of service vulnerability exists in the…7.5
- CVE-2020-6096An exploitable signed comparison vulnerability exists in the…8.1
Are you affected by CVE-2020-6090?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
