Externally Controlled Reference to a Resource in Another Sphere in WAGO products - CVE-2023-4089
Published: November 22, 2023
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to the affected software uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere. A remote administrator can access files which they already have access to through an undocumented local file inclusion.
Affected software
Edge Controller
Touch Panel 600 Standard Line
PFC100
PFC200
Touch Panel 600 Marine Line
Touch Panel 600 Advanced Line
How to mitigate CVE-2023-4089
Edge Controller - update to FW27
Touch Panel 600 Standard Line - update to FW27
PFC100 - update to FW27
PFC200 - update to FW27
Touch Panel 600 Marine Line - update to FW27
Touch Panel 600 Advanced Line - update to FW27