CVE-2023-4089
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: info@cert.vde.com (Secondary)
Description
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 19 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Compact Controller 100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 18 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Edge Controller | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc200 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Advanced | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Marine | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 26 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Standard | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.