Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wago
Subscribe
|
Compact Controller 100
Subscribe
Compact Controller 100 Firmware
Subscribe
Edge Controller
Subscribe
Edge Controller Firmware
Subscribe
Pfc100
Subscribe
Pfc100 Firmware
Subscribe
Pfc200
Subscribe
Pfc200 Firmware
Subscribe
Touch Panel 600 Advanced
Subscribe
Touch Panel 600 Advanced Firmware
Subscribe
Touch Panel 600 Marine
Subscribe
Touch Panel 600 Marine Firmware
Subscribe
Touch Panel 600 Standard
Subscribe
Touch Panel 600 Standard Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44046 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2023-015/ |
|
History
Wed, 02 Oct 2024 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Wed, 02 Oct 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-10-02T05:34:25.860Z
Reserved: 2023-06-23T09:01:09.552Z
Link: CVE-2023-3379
No data.
Status : Modified
Published: 2023-11-20T08:15:44.280
Modified: 2024-11-21T08:17:08.337
Link: CVE-2023-3379
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD