LOW · 2.7

CVE-2023-4089

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a ...

Vulnerability Description

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

CVSS Score

2.7

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WagoCompact Controller 100 Firmware>= 19, <= 26
WagoCompact Controller 100-
WagoEdge Controller Firmware>= 18, <= 26
WagoEdge Controller-
WagoPfc100 Firmware>= 16, <= 26
WagoPfc100-
WagoPfc200 Firmware>= 16, <= 26
WagoPfc200-
WagoTouch Panel 600 Advanced Firmware>= 16, <= 26
WagoTouch Panel 600 Advanced-
WagoTouch Panel 600 Marine Firmware>= 16, <= 26
WagoTouch Panel 600 Marine-
WagoTouch Panel 600 Standard Firmware>= 16, <= 26
WagoTouch Panel 600 Standard-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-4089?

CVE-2023-4089 is a vulnerability with a CVSS score of 2.7 (LOW). On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a ...

How severe is CVE-2023-4089?

CVE-2023-4089 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-4089?

Check the references section above for vendor advisories and patch information. Affected products include: Wago Compact Controller 100 Firmware, Wago Compact Controller 100, Wago Edge Controller Firmware, Wago Edge Controller, Wago Pfc100 Firmware.