WAGO: Multiple products vulnerable to local file inclusion
Vulnerability Description
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4089
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Floris Hendriks and Jeroen Wijenbergh from Radboud University
More from WAGO
View All →Affected Vendor
WAGO
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.