S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-1698 Scanner

CVE-2023-1698 scanner - Remote Command Execution vulnerability in WAGO

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-1698
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Compact Controller CC100by WAGO
FW20
Edge Controllerby WAGO
FW22
PFC100by WAGO
FW20
PFC200by WAGO
FW20
Updated Aug 22, 2026View on NVD →
Detail

WAGO's Compact Controller 100 is an advanced industrial control system widely utilized across various sectors for automating processes and operations. This product is integral to modern industrial setups, offering precision control, monitoring, and data acquisition capabilities. Its firmware plays a critical role in ensuring the reliable operation of machinery and processes, impacting production efficiency and safety. The device is favored for its compact design, scalability, and ease of integration into existing systems, serving as a cornerstone of industrial automation solutions.

CVE-2023-1698 represents a critical vulnerability within the WAGO Compact Controller 100 Firmware that enables unauthenticated, remote attackers to execute arbitrary commands. This vulnerability stems from inadequate input validation, allowing attackers to inject and execute commands, potentially leading to the creation of new users, alteration of device configurations, or full system compromise. The severity of this flaw cannot be understated, as it directly impacts the operational integrity and security of affected devices.

The exploitation mechanism involves sending specially crafted POST requests to a vulnerable endpoint in the device's web-based management interface (/wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php). The vulnerability allows for the injection of arbitrary commands through the 'package' parameter, bypassing authentication mechanisms. Successful exploitation could result in unauthorized command execution, providing attackers with the ability to alter system configurations, disrupt services, or gain complete control over the affected system.

Exploiting this vulnerability can have severe consequences, including unauthorized system access, data exfiltration, service disruption (Denial of Service), and the potential for a full system compromise. Such breaches can lead to significant operational downtime, compromise of sensitive information, and undermine the security posture of the entire industrial environment. The critical nature of this vulnerability underscores the importance of securing industrial control systems against remote attacks.

S4E (S4E) provides a comprehensive platform for detecting and managing vulnerabilities like CVE-2023-1698. Our service enables businesses to proactively identify security weaknesses in their digital infrastructure, including critical industrial control systems. By joining S4E, you gain access to state-of-the-art scanning technology, expert analysis, and actionable remediation advice, helping to safeguard your systems against emerging threats and ensuring continuity of operations. Elevate your cybersecurity defenses with S4E and protect your assets from sophisticated cyber-attacks.

 

References

Solution Advice
  1. Immediately apply the latest security patches and updates provided by WAGO for the Compact Controller 100 Firmware to mitigate this vulnerability.
  2. Ensure that all devices are behind a firewall and not directly accessible from the internet to reduce the risk of remote attacks.
  3. Implement strict access controls and network segmentation to limit the potential impact of a compromise.
  4. Regularly monitor and review device logs for any unusual activities that may indicate attempted or successful exploitation.
  5. Conduct periodic security assessments and penetration testing to identify and address vulnerabilities in a timely manner, enhancing overall system resilience.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.