ZeroHour

CVE-2019-5106

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p27
Published
()
Modified
Description

A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.

Vendors
wago
Products
e\!cockpit
Weakness
CWE-798
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.