CVE-2023-3379: WAGO: Improper Privilege Management in web-based management
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3379?
CVE-2023-3379 is a vulnerability in Wago web-based management that allows a local authenticated attacker to change the passwords of other non-admin users and escalate privileges.
Which products are affected by CVE-2023-3379?
The Wago Compact Controller 100 Firmware (up to version 25), Wago Edge Controller Firmware (up to version 25), WAGO PFC100 Firmware (up to version 22), WAGO PFC200 Firmware (up to version 22), Wago Touch Panel 600 Advanced Firmware (up to version 25), Wago Touch Panel 600 Marine Firmware (up to version 25), and Wago Touch Panel 600 Standard Firmware (up to version 25) are affected.
What is the severity of CVE-2023-3379?
CVE-2023-3379 has a severity rating of 5.3 (medium).
How can I fix CVE-2023-3379?
To fix CVE-2023-3379, users should update their firmware to the latest version provided by Wago and ensure proper privilege management.
Where can I find more information about CVE-2023-3379?
More information about CVE-2023-3379 can be found on the VDE CERT website at the following link: [VDE-2023-015](https://cert.vde.com/en/advisories/VDE-2023-015/).