Use of a broken or risky cryptographic algorithm in WAGO e!COCKPIT - CVE-2019-5106
Published: March 18, 2020
WAGO e!COCKPIT
Detailed vulnerability description
The vulnerability allows a local attacker to gain access to sensitive information on the target system.
The vulnerability exists due to the affected products use a weak cryptographic algorithm in the authentication functionality. A local attacker with access to communications between e!Cockpit and CoDeSyS Gateway can recover the password of any user attempting to log in, in plain text.