Timing Discrepancy Vulnerability in WAGO PFC100/200 Controllers
CVE-2019-5135
What is CVE-2019-5135?
A timing discrepancy vulnerability affects the authentication process of the Web-Based Management (WBM) application in WAGO PFC100 and PFC200 controllers. This flaw arises from the improper use of the PHP crypt() function, potentially allowing attackers to reveal hashed user credentials. Users of specific firmware versions of the WAGO controllers are advised to assess their systems and apply necessary updates to mitigate any risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.01.07(13)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
