CVE-2023-1698

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-007/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*

History

26 May 2023, 17:09

Type Values Removed Values Added
CPE cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory
First Time Wago touch Panel 600 Marine
Wago compact Controller 100 Firmware
Wago touch Panel 600 Standard Firmware
Wago touch Panel 600 Standard
Wago pfc200
Wago pfc100 Firmware
Wago pfc200 Firmware
Wago touch Panel 600 Advanced
Wago touch Panel 600 Advanced Firmware
Wago edge Controller Firmware
Wago touch Panel 600 Marine Firmware
Wago compact Controller 100
Wago
Wago edge Controller
Wago pfc100

Information

Published : 2023-05-15 09:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-1698

Mitre link : CVE-2023-1698

CVE.ORG link : CVE-2023-1698


JSON object : View

Products Affected

wago

  • touch_panel_600_marine_firmware
  • pfc200_firmware
  • touch_panel_600_advanced_firmware
  • compact_controller_100_firmware
  • pfc200
  • touch_panel_600_standard
  • edge_controller
  • pfc100_firmware
  • edge_controller_firmware
  • pfc100
  • touch_panel_600_marine
  • touch_panel_600_advanced
  • touch_panel_600_standard_firmware
  • compact_controller_100
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')