ID

VAR-202310-0385


CVE

CVE-2023-4089


TITLE

plural  WAGO  Vulnerability of external controllable references to other domain resources in the product

Trust: 0.8

sources: JVNDB: JVNDB-2023-007590

DESCRIPTION

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected. WAGO The following vulnerabilities exist in multiple products provided by . * Externally controllable reference to another region resource (CWE-610) - CVE-2023-4089If the vulnerability is exploited, it may be affected as follows

Trust: 1.71

sources: NVD: CVE-2023-4089 // JVNDB: JVNDB-2023-007590 // VULMON: CVE-2023-4089

AFFECTED PRODUCTS

vendor:wagomodel:pfc200scope:lteversion:26

Trust: 1.0

vendor:wagomodel:touch panel 600 advancedscope:lteversion:26

Trust: 1.0

vendor:wagomodel:touch panel 600 advancedscope:gteversion:16

Trust: 1.0

vendor:wagomodel:touch panel 600 standardscope:gteversion:16

Trust: 1.0

vendor:wagomodel:touch panel 600 standardscope:lteversion:26

Trust: 1.0

vendor:wagomodel:touch panel 600 marinescope:gteversion:16

Trust: 1.0

vendor:wagomodel:pfc100scope:lteversion:26

Trust: 1.0

vendor:wagomodel:compact controller 100scope:gteversion:19

Trust: 1.0

vendor:wagomodel:edge controllerscope:lteversion:26

Trust: 1.0

vendor:wagomodel:pfc100scope:gteversion:16

Trust: 1.0

vendor:wagomodel:edge controllerscope:gteversion:18

Trust: 1.0

vendor:wagomodel:compact controller 100scope:lteversion:26

Trust: 1.0

vendor:wagomodel:pfc200scope:gteversion:16

Trust: 1.0

vendor:wagomodel:touch panel 600 marinescope:lteversion:26

Trust: 1.0

vendor:wagomodel:edge controllerscope: - version: -

Trust: 0.8

vendor:wagomodel:touch panel 600 advancedscope: - version: -

Trust: 0.8

vendor:wagomodel:touch panel 600 standardscope: - version: -

Trust: 0.8

vendor:wagomodel:pfc200scope: - version: -

Trust: 0.8

vendor:wagomodel:compact controller cc100scope: - version: -

Trust: 0.8

vendor:wagomodel:touch panel 600 marinescope: - version: -

Trust: 0.8

vendor:wagomodel:pfc100scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-007590 // NVD: CVE-2023-4089

CVSS

SEVERITY

CVSSV2

CVSSV3

info@cert.vde.com: CVE-2023-4089
value: LOW

Trust: 1.0

OTHER: JVNDB-2023-007590
value: LOW

Trust: 0.8

info@cert.vde.com: CVE-2023-4089
baseSeverity: LOW
baseScore: 2.7
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.2
impactScore: 1.4
version: 3.1

Trust: 1.0

OTHER: JVNDB-2023-007590
baseSeverity: LOW
baseScore: 2.7
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-007590 // NVD: CVE-2023-4089

PROBLEMTYPE DATA

problemtype:CWE-610

Trust: 1.0

problemtype:Externally controllable reference to another region resource (CWE-610) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-007590 // NVD: CVE-2023-4089

PATCH

title:WAGO Global | Reliable Solutions for Many Sectors and Industoriesurl:https://www.wago.com/global/

Trust: 0.8

sources: JVNDB: JVNDB-2023-007590

EXTERNAL IDS

db:NVDid:CVE-2023-4089

Trust: 2.7

db:CERT@VDEid:VDE-2023-046

Trust: 1.9

db:JVNid:JVNVU96020889

Trust: 0.8

db:ICS CERTid:ICSA-23-325-01

Trust: 0.8

db:JVNDBid:JVNDB-2023-007590

Trust: 0.8

db:VULMONid:CVE-2023-4089

Trust: 0.1

sources: VULMON: CVE-2023-4089 // JVNDB: JVNDB-2023-007590 // NVD: CVE-2023-4089

REFERENCES

url:https://cert.vde.com/en/advisories/vde-2023-046/

Trust: 1.1

url:http://jvn.jp/vu/jvnvu96020889/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-4089

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-325-01

Trust: 0.8

url:https://cert.vde.com/de/advisories/vde-2023-046/

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/610.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-4089 // JVNDB: JVNDB-2023-007590 // NVD: CVE-2023-4089

SOURCES

db:VULMONid:CVE-2023-4089
db:JVNDBid:JVNDB-2023-007590
db:NVDid:CVE-2023-4089

LAST UPDATE DATE

2024-08-14T13:19:43.329000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-4089date:2023-10-17T00:00:00
db:JVNDBid:JVNDB-2023-007590date:2023-11-24T04:24:00
db:NVDid:CVE-2023-4089date:2023-10-24T18:00:38.507

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-4089date:2023-10-17T00:00:00
db:JVNDBid:JVNDB-2023-007590date:2023-11-24T00:00:00
db:NVDid:CVE-2023-4089date:2023-10-17T07:15:10.090