CVE-2023-4089
WAGO: Multiple products vulnerable to local file inclusion
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
WAGO · Compact Controller CC100WAGO · Edge ControllerWAGO · PFC100WAGO · PFC200WAGO · Touch Panel 600 Advanced LineWAGO · Touch Panel 600 Marine LineWAGO · Touch Panel 600 Standard LineWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →