CVE-2023-4089 Vulnerability Details

  /     /     /  

CVE-2023-4089 Metadata Quick Info

CVE Published: 17/10/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: CERTVDE | Vendor: WAGO | Product: Compact Controller CC100
Status : PUBLISHED

CVE-2023-4089 Description

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Metrics

CVSS Version: 3.1 | Base Score: 2.7 LOW
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* HIGH
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-610
CWE Name: CWE-610 Externally Controlled Reference to a Resource in Another Sphere
Source: WAGO

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).