CVE-2023-3379 MEDIUM

CVE-2023-3379: WAGO: Improper Privilege Management in web-based management

Vendor Wago
Product Compact Controller 100 (751-9301)
Weakness CWE-863 · Incorrect authorization
Published November 20, 2023
Last update October 2, 2024

CVSS base score

5.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Key dates

02Disclosure timeline

November 20, 2023 CVE published
October 2, 2024 Record updated