CVE-2023-3379

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/11/2023
Last modified:
02/10/2024

Description

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:* 25 (including)
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:* 25 (including)
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:* 22 (excluding)
cpe:2.3:o:wago:pfc100_firmware:22:-:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:22:patch_1:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:* 22 (excluding)
cpe:2.3:o:wago:pfc200_firmware:22:-:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:22:patch_1:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:23:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:24:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:* 25 (including)


References to Advisories, Solutions, and Tools