Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-1698— WAGO: WBM Command Injection in multiple products

CVSS 9.8 · Critical EPSS 93.76% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-1698

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WAGO: WBM Command Injection in multiple products
Source: NVD (National Vulnerability Database)
Vulnerability Description
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款WAGO产品操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WAGO PFC100等都是德国万可(WAGO)公司的产品。WAGO PFC100是一款可编程逻辑控制器(PLC)。WAGO Compact Controller CC100是一个紧凑型控制器。WAGO Edge Controller是一个边缘控制器。 WAGO Compact Controller CC100、Edge Controller、PFC100、PFC200、Touch Panel 600 Advanced Line、Touch Panel 600 Marine Line、Touch Pane
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
WAGOCompact Controller CC100 FW20 ~ FW22 -
WAGOEdge Controller FW22 -
WAGOPFC100 FW20 ~ FW22 -
WAGOPFC200 FW20 ~ FW22 -
WAGOTouch Panel 600 Advanced Line FW22 -
WAGOTouch Panel 600 Marine Line FW22 -
WAGOTouch Panel 600 Standard Line FW22 -

II. Public POCs for CVE-2023-1698

#POC DescriptionSource LinkShenlong Link
1WAGO Remote Exploit Tool for CVE-2023-1698https://github.com/Chocapikk/CVE-2023-1698POC Details
2Nonehttps://github.com/deIndra/CVE-2023-1698POC Details
3WAGO系统远程代码执行漏洞(CVE-2023-1698)https://github.com/thedarknessdied/WAGO-CVE-2023-1698POC Details
4CVE-2023-1698 Proof of Concept (PoC)https://github.com/X3RX3SSec/CVE-2023-1698POC Details
5In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1698.yamlPOC Details
6CVE-2023-1698 exploit with golang https://github.com/ibrahmsql/CVE-2023-1698POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-1698

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2023-1698

No comments yet


Leave a comment