peter bassill · operator
$ cve CVE-2023-1698 JSON

CVE-2023-1698

9.8
CRITICAL · CVSS 3.1 · EPSS 82% (pctl 100)

Patch early

EPSS 82% — above the 10% action threshold.

Description

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS82.04% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2023-05-15
Last modified2026-06-17

Affected (14)

VendorProduct
wagocompact controller 100
wagocompact controller 100 firmware
wagoedge controller
wagoedge controller firmware
wagopfc100
wagopfc100 firmware
wagopfc200
wagopfc200 firmware
wagotouch panel 600 advanced
wagotouch panel 600 advanced firmware
wagotouch panel 600 marine
wagotouch panel 600 marine firmware
wagotouch panel 600 standard
wagotouch panel 600 standard firmware

References

→ the Explorer  ·  watch your stack  ·  NVD