Regular Expression without Anchors in Wago PFC200 Controller and WAGO PFC100 Controller - CVE-2019-5134
Published: March 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the regular expression without anchors issue in the Web-Based Management (WBM) authentication functionality. A remote attacker can use a specially crafted authentication request to bypass regular expression filters and gain access to sensitive information on the target system.
Affected software
WAGO PFC100 Controller