CVE-2023-4089
Estado: ModificadaBaja (2.7)—
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 2.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-610
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-4089",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-4089",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-26T21:49:11.155380Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "WAGO",
"product": "Compact Controller CC100",
"versions": [
{
"status": "affected",
"version": "FW19",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "Edge Controller",
"versions": [
{
"status": "affected",
"version": "FW18",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "PFC100",
"versions": [
{
"status": "affected",
"version": "FW16",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "PFC200",
"versions": [
{
"status": "affected",
"version": "FW16",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "Touch Panel 600 Advanced Line",
"versions": [
{
"status": "affected",
"version": "FW16",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "Touch Panel 600 Marine Line",
"versions": [
{
"status": "affected",
"version": "FW16",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "Touch Panel 600 Standard Line",
"versions": [
{
"status": "affected",
"version": "FW16",
"versionType": "semver",
"lessThanOrEqual": "FW26"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-10-17T07:15:10.090",
"references": [
{
"url": "https://cert.vde.com/en/advisories/VDE-2023-046/",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/en/advisories/VDE-2023-046/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-610"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected."
},
{
"lang": "es",
"value": "En los productos Wago afectados, un atacante remoto con privilegios administrativos puede acceder a archivos a los que ya tiene acceso a través de una inclusión de archivo local no documentada. Este acceso se registra en un archivo de registro diferente al esperado."
}
],
"lastModified": "2026-06-17T06:37:03.327",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A495C583-8184-45A5-81E9-E621A58B7E51",
"versionEndIncluding": "26",
"versionStartIncluding": "19"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:compact_controller_100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "532907AF-7E4A-4065-A799-753FC3313D6C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85625EA0-E44C-4A48-BA05-5D506CFDB678",
"versionEndIncluding": "26",
"versionStartIncluding": "18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2DFC57C8-6AF4-4771-B0A0-744137FBFECF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E5D5929-675F-493C-B3AF-70C7C79D3CEB",
"versionEndIncluding": "26",
"versionStartIncluding": "16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F636354-95A2-4B36-9666-1FA57F185432"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F73AE30-E917-433E-BB67-CA383FCDDAFC",
"versionEndIncluding": "26",
"versionStartIncluding": "16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "688A3248-7EAA-499D-A47C-A4D4900CDBD1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DA3F602-1720-4B4B-A834-BD620D9B1F54",
"versionEndIncluding": "26",
"versionStartIncluding": "16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A8221861-7455-41D5-B310-6AEA822B46CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1FED163-F917-4CBC-83DA-D4D751C9121B",
"versionEndIncluding": "26",
"versionStartIncluding": "16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "83DEFFBC-934D-43BE-92AE-25F8EE8C1E0A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98F0C3C2-DE57-4134-AC3C-3D000A33528A",
"versionEndIncluding": "26",
"versionStartIncluding": "16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E6D7A44C-2D95-4F69-A7DB-435B0A6F9F03"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}