Use of a broken or risky cryptographic algorithm in WAGO e!COCKPIT - CVE-2019-5106

 

Use of a broken or risky cryptographic algorithm in WAGO e!COCKPIT - CVE-2019-5106

Published: March 18, 2020


Vulnerability identifier: #VU26165
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5106
CWE-ID: CWE-327
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to sensitive information on the target system.

The vulnerability exists due to the affected products use a weak cryptographic algorithm in the authentication functionality. A local attacker with access to communications between e!Cockpit and CoDeSyS Gateway can recover the password of any user attempting to log in, in plain text.


Affected software

WAGO e!COCKPIT

How to mitigate CVE-2019-5106

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins