VYPR
Medium severity5.3NVD Advisory· Published Mar 11, 2020· Updated Jun 17, 2026

CVE-2019-5135

CVE-2019-5135

Description

An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Wago/PFC100llm-fuzzy
    Range: 03.00.39(12), 03.01.07(13)
  • Wago/WAGO PFC100 Firmwarev5
    Range: version 03.00.39(12)
  • Range: version 03.00.39(12)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.