CVE-2023-1698

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory

26 May 2023, 17:09

Type Values Removed Values Added
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-007/ - Third Party Advisory
First Time Wago pfc200 Firmware
Wago
Wago compact Controller 100
Wago touch Panel 600 Marine Firmware
Wago touch Panel 600 Advanced Firmware
Wago compact Controller 100 Firmware
Wago pfc100
Wago pfc200
Wago touch Panel 600 Marine
Wago edge Controller
Wago touch Panel 600 Advanced
Wago touch Panel 600 Standard
Wago pfc100 Firmware
Wago touch Panel 600 Standard Firmware
Wago edge Controller Firmware
CPE cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*

15 May 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 09:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1698

Mitre link : CVE-2023-1698

CVE.ORG link : CVE-2023-1698


JSON object : View

Products Affected

wago

  • compact_controller_100
  • edge_controller
  • pfc100_firmware
  • touch_panel_600_standard_firmware
  • touch_panel_600_marine_firmware
  • touch_panel_600_marine
  • touch_panel_600_standard
  • compact_controller_100_firmware
  • pfc200_firmware
  • touch_panel_600_advanced
  • edge_controller_firmware
  • touch_panel_600_advanced_firmware
  • pfc100
  • pfc200
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')