Timing Discrepancy Vulnerability in WAGO PFC100/200 Controllers
CVE-2019-5135

5.3MEDIUM

Key Information:

Vendor
Wago
Vendor
CVE Published:
11 March 2020

Summary

A timing discrepancy vulnerability affects the authentication process of the Web-Based Management (WBM) application in WAGO PFC100 and PFC200 controllers. This flaw arises from the improper use of the PHP crypt() function, potentially allowing attackers to reveal hashed user credentials. Users of specific firmware versions of the WAGO controllers are advised to assess their systems and apply necessary updates to mitigate any risks associated with this vulnerability.

Affected Version(s)

WAGO PFC100 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.00.39(12)

WAGO PFC200 Firmware version 03.01.07(13)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.