PT-2023-2007 · Wago · Wago Touch Panel 600+3
Ryan Pickren
·
Published
2023-02-13
·
Updated
2023-03-07
·
CVE-2022-45140
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WAGO PFC100/PFC200 versions (affected versions not specified)
WAGO CC100 versions (affected versions not specified)
WAGO Edge Controller versions (affected versions not specified)
WAGO Touch Panel 600 versions (affected versions not specified)
Description
The issue is related to the lack of authentication for a critical function in the configuration backend of the software. This could allow a remote attacker to write arbitrary data with root privileges, potentially leading to unauthenticated remote code execution and full system compromise.
Recommendations
For WAGO PFC100/PFC200, consider implementing authentication mechanisms for critical functions to prevent unauthorized access until a patch is available.
For WAGO CC100, restrict access to the configuration backend to minimize the risk of exploitation.
For WAGO Edge Controller, disable any functionality that allows writing arbitrary data with root privileges until a fix is provided.
For WAGO Touch Panel 600, avoid using the configuration backend for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wago Cc100
Wago Edge Controller
Wago Pfc100/Pfc200
Wago Touch Panel 600