← Back to CVE List
Vulnerability Intelligence Report
WAGO: WBM Command Injection in multiple products

CVE-2023-1698

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

Nuclei Template
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:81.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
81.911%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT@VDE · CERT · Germany
Reserved2023-03-29T13:00:05
Published2023-05-15T08:51:27
Last Updated2025-01-23T19:13:09

LINK COPIED TO CLIPBOARD