PFC200 Firmware and Security

Hello,

I would like to know what options are available to keep the system up to date independently of the official firmware updates.

Currently, firmware updates are released at longer intervals, sometimes spanning several months:

However, during this time, new—sometimes critical—security vulnerabilities are regularly disclosed and ideally patched promptly. So far, I have not found any option in the Web-Based Management to update installed packages independently of the firmware. Nor was a functional package manager visible via SSH connection.

What is the recommended approach in this case to close a critical security vulnerability as quickly as possible?

Additionally, the release notes mention that the firmware is available via GitHub. However, the latest release there is already several years old. Is this information in the release notes possibly outdated, or have the corresponding files not yet been published on GitHub?

Thank you in advance for a brief response.

Best regards,
Dennis Roth

Hello, Indeed most security fixes are published with the next firmware.
But some are published before, for example:

In the meantime your system should already be locked down as much as possible:

In order to mitigate any possible zero day hack.

For more information please contact your WAGO tech support/ wago sales rep.