CVE-2023-1698

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory

26 May 2023, 17:09

Type Values Removed Values Added
CPE cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory

15 May 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 09:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1698

Mitre link : CVE-2023-1698

CVE.ORG link : CVE-2023-1698


JSON object : View

Products Affected

wago

  • touch_panel_600_marine_firmware
  • compact_controller_100_firmware
  • touch_panel_600_marine
  • pfc100_firmware
  • edge_controller
  • touch_panel_600_advanced
  • compact_controller_100
  • touch_panel_600_advanced_firmware
  • pfc200
  • touch_panel_600_standard_firmware
  • pfc200_firmware
  • pfc100
  • edge_controller_firmware
  • touch_panel_600_standard
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')