PT-2020-11073 · Wago+1 · Wago Pfc 200+2
Published
2020-03-10
·
Updated
2021-07-21
·
CVE-2019-5135
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC200 Firmware versions 03.00.39(12) through 03.01.07(13)
Description
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP
crypt() function which can be exploited to disclose hashed user credentials.Recommendations
For WAGO PFC100 Firmware version 03.00.39(12), consider disabling the
crypt() function in the WBM application until a patch is available.
For WAGO PFC200 Firmware versions 03.00.39(12) through 03.01.07(13), consider disabling the crypt() function in the WBM application until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php
Wago Pfc100
Wago Pfc 200