VDE-2020-006
Last update
05/14/2025 14:28
Published at
03/09/2020 12:00
Vendor(s)
WAGO GmbH & Co. KG
External ID
VDE-2020-006
CSAF Document
Summary
With special crafted requests it is possible to get sensitive information, in this case the password hashes, by measuring response delay. With a substantial amount of time this data can be used to calculate the passwords of the Web-Based Management users. In case of CVE 2019-5134, the password salt can also be extracted.
Impact
These vulnerabilities allow an experienced attacker who has access to the WBM to reconstruct the passwords hashes of the WBM users by sending specifically constructed requests.
Affected Product(s)
Model no. | Product name | Affected versions |
---|---|---|
750-81xx/xxx-xxx | Hardware PFC100 | Software FW05<=FW14 |
750-82xx/xxx-xxx | Hardware PFC200 | Software FW05<=FW14 |
762-4xxx, 762-5xxx, 762-6xxx | Hardware Touch Panel 600 | Software FW05<=FW14 |
Vulnerabilities
Expand / Collapse allRevision History
Version | Date | Summary |
---|---|---|
1 | 03/09/2020 10:05 | Initial revision. |
2 | 11/06/2024 12:27 | Fix: correct certvde domain, added self-reference |
3 | 05/14/2025 14:28 | Fix: firmware category, version space, added distribution |