CVE-2023-1698

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory

Information

Published : 2023-05-15 09:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1698

Mitre link : CVE-2023-1698

CVE.ORG link : CVE-2023-1698


JSON object : View

Products Affected

wago

  • pfc200_firmware
  • touch_panel_600_standard
  • touch_panel_600_advanced_firmware
  • touch_panel_600_marine_firmware
  • edge_controller
  • pfc100
  • touch_panel_600_standard_firmware
  • pfc100_firmware
  • pfc200
  • edge_controller_firmware
  • compact_controller_100
  • touch_panel_600_marine
  • touch_panel_600_advanced
  • compact_controller_100_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')