CVE-2023-3379

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker  to change the passwords of other non-admin users and thus to escalate non-root privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CERTVDECNA
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
wagocompact_controller_100_firmware
𝑥
≤ 25
wagoedge_controller_firmware
𝑥
≤ 25
wagopfc100_firmware
𝑥
< 22
wagopfc200_firmware
𝑥
< 22
wagotouch_panel_600_advanced_firmware
𝑥
≤ 25
wagotouch_panel_600_marine_firmware
𝑥
≤ 25
wagotouch_panel_600_standard_firmware
𝑥
≤ 25
𝑥
= Vulnerable software versions