2.7

CVE-2023-4089

WAGO: Multiple products vulnerable to local file inclusion

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wago ≫ Compact Controller 100 Firmware Version >= 19 <= 26
   Wago ≫ Compact Controller 100 Version -
Wago ≫ Edge Controller Firmware Version >= 18 <= 26
   Wago ≫ Edge Controller Version -
Wago ≫ Pfc100 Firmware Version >= 16 <= 26
   Wago ≫ Pfc100 Version -
Wago ≫ Pfc200 Firmware Version >= 16 <= 26
   Wago ≫ Pfc200 Version -
Wago ≫ Touch Panel 600 Advanced Firmware Version >= 16 <= 26
   Wago ≫ Touch Panel 600 Advanced Version -
Wago ≫ Touch Panel 600 Marine Firmware Version >= 16 <= 26
   Wago ≫ Touch Panel 600 Marine Version -
Wago ≫ Touch Panel 600 Standard Firmware Version >= 16 <= 26
   Wago ≫ Touch Panel 600 Standard Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

https://cert.vde.com/en/advisories/VDE-2023-046/
Third Party Advisory