2023-11-20 09:00:22 +00:00
{
"id" : "CVE-2023-3379" ,
"sourceIdentifier" : "info@cert.vde.com" ,
"published" : "2023-11-20T08:15:44.280" ,
2023-11-30 17:00:22 +00:00
"lastModified" : "2023-11-30T15:16:28.910" ,
"vulnStatus" : "Analyzed" ,
2023-11-20 09:00:22 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges."
2023-11-20 17:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "La administraci\u00f3n de m\u00faltiples productos basada en web de Wago tiene una vulnerabilidad que permite a un atacante autenticado local cambiar las contrase\u00f1as de otros usuarios que no sean administradores y as\u00ed escalar privilegios no root."
2023-11-20 09:00:22 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "info@cert.vde.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.4
}
]
} ,
"weaknesses" : [
2023-11-30 17:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2023-11-20 09:00:22 +00:00
{
"source" : "info@cert.vde.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-269"
}
]
}
] ,
2023-11-30 17:00:22 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "25" ,
"matchCriteriaId" : "B6F27D52-0A31-4CE5-823B-7DA6DCF291AD"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "532907AF-7E4A-4065-A799-753FC3313D6C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "25" ,
"matchCriteriaId" : "67EF75C3-893E-408D-B3C6-464F3C7AC27D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2DFC57C8-6AF4-4771-B0A0-744137FBFECF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "252F9DAE-5C46-48B3-A74A-8331DE3B5189"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "4815DFF8-0CAE-4C85-9F5B-F64C12F43AB0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:22:patch_1:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F71E8B5-7774-45BB-8B7D-7C38A4B90EA0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F636354-95A2-4B36-9666-1FA57F185432"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "C741BCDD-8485-4DDC-9D51-143F1EE4824E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "B876DC19-0523-41DB-8BD7-1ECC09FCFA01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:22:patch_1:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA491C96-F0CF-4960-8F91-831E80622D5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE108CD0-B451-4ED5-83A1-CCEAACC1B40C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:24:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4E45E9B-3F87-4758-8BCE-BCF79AD225DA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "688A3248-7EAA-499D-A47C-A4D4900CDBD1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "25" ,
"matchCriteriaId" : "AD598E88-4682-43AD-AD12-2763B931416C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A8221861-7455-41D5-B310-6AEA822B46CF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "25" ,
"matchCriteriaId" : "A9018036-B119-472C-A5A3-D0253E2FA425"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "83DEFFBC-934D-43BE-92AE-25F8EE8C1E0A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "25" ,
"matchCriteriaId" : "99BEC3AF-787E-441A-A181-A491E119295B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6D7A44C-2D95-4F69-A7DB-435B0A6F9F03"
}
]
}
]
}
] ,
2023-11-20 09:00:22 +00:00
"references" : [
{
"url" : "https://cert.vde.com/en/advisories/VDE-2023-015/" ,
2023-11-30 17:00:22 +00:00
"source" : "info@cert.vde.com" ,
"tags" : [
"Third Party Advisory"
]
2023-11-20 09:00:22 +00:00
}
]
}