Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
2023-11-20T08:15:44.280
2024-11-21T08:17:08.337
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | wago | compact_controller_100_firmware | ≤ 25 | Yes |
Hardware | wago | compact_controller_100 | - | No |
Operating System | wago | edge_controller_firmware | ≤ 25 | Yes |
Hardware | wago | edge_controller | - | No |
Operating System | wago | pfc100_firmware | < 22 | Yes |
Operating System | wago | pfc100_firmware | 22 | Yes |
Operating System | wago | pfc100_firmware | 22 | Yes |
Hardware | wago | pfc100 | - | No |
Operating System | wago | pfc200_firmware | < 22 | Yes |
Operating System | wago | pfc200_firmware | 22 | Yes |
Operating System | wago | pfc200_firmware | 22 | Yes |
Operating System | wago | pfc200_firmware | 23 | Yes |
Operating System | wago | pfc200_firmware | 24 | Yes |
Hardware | wago | pfc200 | - | No |
Operating System | wago | touch_panel_600_advanced_firmware | ≤ 25 | Yes |
Hardware | wago | touch_panel_600_advanced | - | No |
Operating System | wago | touch_panel_600_marine_firmware | ≤ 25 | Yes |
Hardware | wago | touch_panel_600_marine | - | No |
Operating System | wago | touch_panel_600_standard_firmware | ≤ 25 | Yes |
Hardware | wago | touch_panel_600_standard | - | No |