CVE-2019-5106

MEDIUM

WAGO e!Cockpit <1.5.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0898

Scores

CVSS v3 5.5
EPSS 0.0034
EPSS Percentile 25.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-798
Status published
Products (1)
wago/e\!cockpit 1.5.1.1
Published Mar 11, 2020
Tracked Since Feb 18, 2026