First published: Tue Oct 17 2023(Updated: )
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Wago Compact Controller 100 Firmware | >=19<=26 | |
Wago Compact Controller 100 | ||
All of | ||
Wago Edge Controller Firmware | >=18<=26 | |
Wago Edge Controller | ||
All of | ||
WAGO PFC100 Firmware | >=16<=26 | |
WAGO PFC100 | ||
All of | ||
WAGO PFC200 Firmware | >=16<=26 | |
WAGO PFC200 | ||
All of | ||
Wago Touch Panel 600 Advanced Firmware | >=16<=26 | |
Wago Touch Panel 600 Advanced | ||
All of | ||
Wago Touch Panel 600 Marine Firmware | >=16<=26 | |
Wago Touch Panel 600 Marine | ||
All of | ||
Wago Touch Panel 600 Standard Firmware | >=16<=26 | |
Wago Touch Panel 600 Standard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-4089.
CVE-2023-4089 has a severity value of 2.7 (low).
The affected Wago products are: Wago Compact Controller 100 Firmware (versions 19 to 26), Wago Edge Controller Firmware (versions 18 to 26), WAGO PFC100 Firmware (versions 16 to 26), WAGO PFC200 Firmware (versions 16 to 26), Wago Touch Panel 600 Advanced Firmware (versions 16 to 26), Wago Touch Panel 600 Marine Firmware (versions 16 to 26), and Wago Touch Panel 600 Standard Firmware (versions 16 to 26).
A remote attacker with administrative privileges can access files to which they already have access through an undocumented local file inclusion.
The unauthorized access is logged in a different log file than expected.