ZeroHour

CVE-2023-3379

CVSS 3.1
5.3 medium
EPSS
<1%p10
Published
()
Modified
Description

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Vendors
wago
Products
compact controller 100 firmware, edge controller firmware, pfc100 firmware, pfc200 firmware, touch panel 600 advanced firmware, touch panel 600 marine firmware, touch panel 600 standard firmware
Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.