Wago PFC100/200 Web-Based Management FastCGI configuration insufficient resource pool denial of service (CVE-2019-5149)

high Tenable OT Security Plugin ID 500802

Synopsis

The remote OT asset is affected by a vulnerability.

Description

The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default configuration of this module appears to limit the number of concurrent php-cgi processes to two, which can be abused to cause a denial of service of the entire web server. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12) and version 03.02.02(14).

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://talosintelligence.com/vulnerability_reports/TALOS-2019-0939

Plugin Details

Severity: High

ID: 500802

Version: 1.3

Type: remote

Family: Tenable.ot

Published: 2/14/2023

Updated: 4/22/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2019-5149

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:wago:pfc100_firmware:03.00.39%2812%29, cpe:/o:wago:pfc100_firmware:03.01.07%2813%29, cpe:/o:wago:pfc200_firmware:03.00.39%2812%29, cpe:/o:wago:pfc200_firmware:03.01.07%2813%29

Required KB Items: Tenable.ot/Wago

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/11/2020

Vulnerability Publication Date: 3/11/2020

Reference Information

CVE: CVE-2019-5149

CWE: 400