CVE Vulnerabilities

CVE-2023-4089

Externally Controlled Reference to a Resource in Another Sphere

Published: Oct 17, 2023 | Modified: Oct 24, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Compact_controller_100_firmware Wago 19 (including) 26 (including)

References