PT-2023-3026 · Wago · Wago Touch Panel 600+4

Quentin Kaiser

·

Publicado

2023-05-04

·

Atualizado

2023-09-15

·

CVE-2023-1698

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WAGO PFC100 versions >=16 and <=23 WAGO PFC200 versions >=16 and <=23 WAGO CC100 versions >=16 and <=23 WAGO Edge Controller versions >=16 and <=23 WAGO Touch Panel 600 Standard, Advanced/Marine Line versions >=16 and <=23
Description A vulnerability in WAGO products allows an unauthenticated, remote attacker to create new users and change the device configuration, which can result in unintended behavior, Denial of Service, and full system compromise. The issue is related to insufficient input validation, which can allow an attacker to access confidential data, compromise data integrity, and cause a denial of service. Approximately 15,961 devices may be affected.
Recommendations For WAGO PFC100 versions >=16 and <=23, update to a version outside of this range to mitigate the risk. For WAGO PFC200 versions >=16 and <=23, update to a version outside of this range to mitigate the risk. For WAGO CC100 versions >=16 and <=23, update to a version outside of this range to mitigate the risk. For WAGO Edge Controller versions >=16 and <=23, update to a version outside of this range to mitigate the risk. For WAGO Touch Panel 600 Standard, Advanced/Marine Line versions >=16 and <=23, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the device configuration to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03091
CVE-2023-1698

Produtos afetados

Wago Cc100
Wago Edge Controller
Wago Pfc100
Wago Pfc 200
Wago Touch Panel 600