← All CVEs

CVE-2023-1698

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

9.8
CVSS
82.0%
EPSS (exploit prob.)
100th
EPSS percentile
2023-05-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
wagocompact_controller_100_firmware>= 20, <= 23
wagocompact_controller_100all versions
wagoedge_controller_firmware22
wagoedge_controllerall versions
wagopfc100_firmware>= 20, <= 23
wagopfc100all versions
wagopfc200_firmware>= 20, <= 23
wagopfc200all versions
wagotouch_panel_600_advanced_firmware22
wagotouch_panel_600_advancedall versions
wagotouch_panel_600_marine_firmware22
wagotouch_panel_600_marineall versions
wagotouch_panel_600_standard_firmware22
wagotouch_panel_600_standardall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-1698