CVE-2019-5135
published 2020-03-11CVE-2019-5135: An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.02%
59.6th percentile
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | pfc100_firmware | — | — |
| wago | pfc200_firmware | — | — |
| wago | pfc200_firmware | — | — |
| wago | wago_pfc100_firmware | — | — |
| wago | wago_pfc200_firmware | — | — |
| wago | wago_pfc200_firmware | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that arise
blogs_talos·2020-10-21·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that arise
## Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that arise
Report and research by Kelly Leuschner.
WAGO makes several programmable automation controllers that are used in many industries including automotive, rail, power engineering, manufacturing and building management. Cisco Talos discovered 41 vulnerabilities in their PFC200 and PFC100 controllers. In accordance with our coordinated disclosure policy, Cisco Talos worked with WAGO to ensure that these issues were resolved and that a firmware update is available for affected customers.
Since a patch has been available to affected customers for some time, we wanted to take this opportunity to discuss several attack chains that exploit WAGO’s cloud connectivity client known as “dataagent” t
Talos
Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that arise
blogs_talos·2020-10-21·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that arise
Report and research by Kelly Leuschner.
WAGO makes several programmable automation controllers that are used in many industries including automotive, rail, power engineering, manufacturing and building management. Cisco Talos discovered 41 vulnerabilities in their PFC200 and PFC100 controllers. In accordance with our coordinated disclosure policy, Cisco Talos worked with WAGO to ensure that these issues were resolved and that a firmware update is available for affected customers.
Since a patch has been available to affected customers for some time, we wanted to take this opportunity to discuss several attack chains that exploit WAGO’s cloud connectivity client known as “dataagent” to gain root access to the device. You can also catch a technical presentation of these vulnerabilities at t
Talos
Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities
blogs_talos·2020-03-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities
Patrick DeSantis, Carl Hurd, Kelly Leuschner and Lilith [-_-]; of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
Cisco Talos recently discovered several vulnerabilities in multiple products from the company WAGO. WAGO produces a line of automation software called “e!COCKPIT,” an integrated development
environment that aims to speed up automation tasks and machine and system startup. The e!COCKPIT software interfaces with different automation controllers, including the PFC100 and PFC200. The vulnerabilities described here exist within the e!COCKPIT software or the two associated automation controllers. A remote attacker could exploit these vulnerabilities to carry out a variety of malicious activities, including command injection, information disclosure and remote code
Talos
Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities
blogs_talos·2020-03-09·CVSS 7.5
[HIGH] Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities
## Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities
Patrick DeSantis, Carl Hurd, Kelly Leuschner and Lilith [-_-]; of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw. Cisco Talos recently discovered several vulnerabilities in multiple products from the company WAGO. WAGO produces a line of automation software called “e!COCKPIT,” an integrated development
environment that aims to speed up automation tasks and machine and system startup. The e!COCKPIT software interfaces with different automation controllers, including the PFC100 and PFC200. The vulnerabilities described here exist within the e!COCKPIT software or the two associated automation controllers. A remote attacker could exploit these vulnerabilities to carry out a varie
2020-03-11
Published