VulnerabilityModified
CVE-2023-1698
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
CRITICAL 9.8EPSS 82.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 82.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 82.04% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- wago/compact controller 100 firmware · wago/edge controller firmware · wago/pfc100 firmware · wago/pfc200 firmware · wago/touch panel 600 advanced firmware · wago/touch panel 600 marine firmware · wago/touch panel 600 standard firmware
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en/advisories/VDE-2023-007/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-007/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.