9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 20 to 23 |
| Running on/with | Platform Versions |
|---|---|
Wago Compact Controller 100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Edge Controller | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 20 to 23 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 20 to 23 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc200 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Advanced | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Marine | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Standard | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.