cbcvebase.
CVE-2023-1698
published 2023-05-15

CVE-2023-1698: In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

Affected

17 ranges
VendorProductVersion rangeFixed in
wagocompact_controller_100_firmware20 – 23
wagocompact_controller_cc100
wagocompact_controller_cc100FW20 – FW22
wagoedge_controller
wagoedge_controller_firmware
wagopfc100
wagopfc100FW20 – FW22
wagopfc100_firmware20 – 23
wagopfc200
wagopfc200FW20 – FW22
wagopfc200_firmware20 – 23
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_line
wagotouch_panel_600_marine_firmware
wagotouch_panel_600_marine_line
wagotouch_panel_600_standard_firmware
wagotouch_panel_600_standard_line

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL