CVE-2023-4089

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2023
Last modified:
24/10/2023

Description

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:* 19 (including) 26 (including)
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:* 18 (including) 26 (including)
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:* 16 (including) 26 (including)
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:* 16 (including) 26 (including)
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:* 16 (including) 26 (including)
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:* 16 (including) 26 (including)
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:* 16 (including) 26 (including)
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools