← back
CVE-2023-4089

WAGO: Multiple products vulnerable to local file inclusion

CVSS 2.7 LOWEPSS 0.5%CWE-610
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →