Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Project Subscriptions

Vendors Products
Compact Controller 100 Subscribe
Compact Controller 100 Firmware Subscribe
Edge Controller Subscribe
Edge Controller Firmware Subscribe
Pfc100 Firmware Subscribe
Pfc200 Firmware Subscribe
Touch Panel 600 Advanced Subscribe
Touch Panel 600 Advanced Firmware Subscribe
Touch Panel 600 Marine Subscribe
Touch Panel 600 Marine Firmware Subscribe
Touch Panel 600 Standard Subscribe
Touch Panel 600 Standard Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44046 Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Oct 2024 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 02 Oct 2024 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-10-02T05:34:25.860Z

Reserved: 2023-06-23T09:01:09.552Z

Link: CVE-2023-3379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-20T08:15:44.280

Modified: 2024-11-21T08:17:08.337

Link: CVE-2023-3379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses