cbcvebase.
CVE-2023-4089
published 2023-10-17

CVE-2023-4089: On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local…

PriorityP410low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.47%
37.6th percentile
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Affected

15 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
wagocompact_controller_100_firmware19 – 26
wagocompact_controller_cc100FW19 – FW26
wagoedge_controllerFW18 – FW26
wagoedge_controller_firmware18 – 26
wagopfc100FW16 – FW26
wagopfc100_firmware16 – 26
wagopfc200FW16 – FW26
wagopfc200_firmware16 – 26
wagotouch_panel_600_advanced_firmware16 – 26
wagotouch_panel_600_advanced_lineFW16 – FW26
wagotouch_panel_600_marine_firmware16 – 26
wagotouch_panel_600_marine_lineFW16 – FW26
wagotouch_panel_600_standard_firmware16 – 26
wagotouch_panel_600_standard_lineFW16 – FW26
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.