CVE-2023-4089: WAGO: Multiple products vulnerable to local file inclusion
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-4089.
What is the severity of CVE-2023-4089?
CVE-2023-4089 has a severity value of 2.7 (low).
Which Wago products are affected by CVE-2023-4089?
The affected Wago products are: Wago Compact Controller 100 Firmware (versions 19 to 26), Wago Edge Controller Firmware (versions 18 to 26), WAGO PFC100 Firmware (versions 16 to 26), WAGO PFC200 Firmware (versions 16 to 26), Wago Touch Panel 600 Advanced Firmware (versions 16 to 26), Wago Touch Panel 600 Marine Firmware (versions 16 to 26), and Wago Touch Panel 600 Standard Firmware (versions 16 to 26).
What can a remote attacker with administrative privileges do with CVE-2023-4089?
A remote attacker with administrative privileges can access files to which they already have access through an undocumented local file inclusion.
How is the unauthorized access logged in CVE-2023-4089?
The unauthorized access is logged in a different log file than expected.