Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5106

Опубликовано: 11 мар. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wago:e\!cockpit:1.5.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-798

Связанные уязвимости

github
больше 3 лет назад

A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.

EPSS

Процентиль: 20%
0.00063
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-798