Timing Discrepancy Vulnerability in WAGO PFC100/200 Controllers
CVE-2019-5135
5.3MEDIUM
Summary
A timing discrepancy vulnerability affects the authentication process of the Web-Based Management (WBM) application in WAGO PFC100 and PFC200 controllers. This flaw arises from the improper use of the PHP crypt() function, potentially allowing attackers to reveal hashed user credentials. Users of specific firmware versions of the WAGO controllers are advised to assess their systems and apply necessary updates to mitigate any risks associated with this vulnerability.
Affected Version(s)
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.00.39(12)
WAGO PFC200 Firmware version 03.01.07(13)
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved