Denial of Service Vulnerability in WAGO PFC100 and PFC2000 Products
CVE-2019-5149
What is CVE-2019-5149?
The WBM web application deployed on WAGO PFC100 and PFC2000 devices running on outdated firmware versions is susceptible to a denial of service scenario. Owing to the default configuration of the FastCGI module, the application limits the number of concurrent php-cgi processes to only two. This limitation can be exploited, leading to a potential overload and, consequently, a denial of service for the entire web server. Users of these devices should ensure they are running the latest firmware versions to mitigate any associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WAGO PFC100 Firmware version 03.00.39(12)
WAGO PFC100 Firmware version 03.02.02(14)
WAGO PFC200 Firmware version 03.00.39(12)
