Vulnerabilities > CVE-2023-3379 - Incorrect Authorization vulnerability in Wago products

047910
CVSS 5.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
local
low complexity
wago
CWE-863

Summary

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

Vulnerable Configurations

Part Description Count
OS
Wago
51
Hardware
Wago
7

Common Weakness Enumeration (CWE)