CVE-2023-4089

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-046/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-17 07:15

Updated : 2023-10-24 18:00


NVD link : CVE-2023-4089

Mitre link : CVE-2023-4089

CVE.ORG link : CVE-2023-4089


JSON object : View

Products Affected

wago

  • edge_controller
  • pfc200_firmware
  • touch_panel_600_standard_firmware
  • compact_controller_100
  • touch_panel_600_marine
  • touch_panel_600_advanced_firmware
  • touch_panel_600_standard
  • touch_panel_600_advanced
  • pfc200
  • touch_panel_600_marine_firmware
  • edge_controller_firmware
  • pfc100
  • pfc100_firmware
  • compact_controller_100_firmware
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere