CVE-2023-3379: Wago Compact Controller 100 Firmware
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
Affected products
- Wago Compact Controller 100 Firmware: up to and including 25
- Wago Edge Controller Firmware: up to and including 25
- Wago PFC100 Firmware: before 22 (fixed in 22); version 22 only
- Wago PFC200 Firmware: before 22 (fixed in 22); version 22 only; version 23 only; version 24 only
- Wago Touch Panel 600 Advanced Firmware: up to and including 25
- Wago Touch Panel 600 Marine Firmware: up to and including 25
- Wago Touch Panel 600 Standard Firmware: up to and including 25
Published 2023-11-20. Last modified 2026-06-17.