2.7

CVE-2023-4089

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Data is provided by the National Vulnerability Database (NVD)
WagoCompact Controller 100 Firmware Version >= 19 <= 26
   WagoCompact Controller 100 Version-
WagoEdge Controller Firmware Version >= 18 <= 26
   WagoEdge Controller Version-
WagoPfc100 Firmware Version >= 16 <= 26
   WagoPfc100 Version-
WagoPfc200 Firmware Version >= 16 <= 26
   WagoPfc200 Version-
WagoTouch Panel 600 Advanced Firmware Version >= 16 <= 26
   WagoTouch Panel 600 Advanced Version-
WagoTouch Panel 600 Marine Firmware Version >= 16 <= 26
   WagoTouch Panel 600 Marine Version-
WagoTouch Panel 600 Standard Firmware Version >= 16 <= 26
   WagoTouch Panel 600 Standard Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.262
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
info@cert.vde.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.