CVE-2023-1698: WAGO: WBM Command Injection in multiple products
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1698?
CVE-2023-1698 refers to a vulnerability found in multiple products of WAGO, allowing an unauthenticated remote attacker to create new users and change device configuration, resulting in unintended behavior, denial of service, and full system compromise.
Which products are affected by CVE-2023-1698?
The vulnerability affects multiple products of WAGO, including Compact Controller 100 Firmware (versions 20 to 23), PFC100 Firmware (versions 20 to 23), PFC200 Firmware (versions 20 to 23), Touch Panel 600 Advanced Firmware (version 22), Touch Panel 600 Marine Firmware (version 22), and Touch Panel 600 Standard Firmware (version 22).
What is the severity of CVE-2023-1698?
The severity of CVE-2023-1698 is rated as critical, with a severity value of 9.8.
How can an attacker exploit CVE-2023-1698?
An unauthenticated remote attacker can exploit CVE-2023-1698 by creating new users and changing device configuration, leading to unintended behavior, denial of service, and potential full system compromise.
Is there a fix for CVE-2023-1698?
At the moment, there is no available fix for CVE-2023-1698. It is advised to follow the recommendations provided by WAGO and monitor for updates from the vendor.