Описание
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
Ссылки
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 02 (исключая)
Одновременно
cpe:2.3:o:wago:762-3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:762-3000:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 02 (исключая)
Одновременно
cpe:2.3:o:wago:762-3001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:762-3001:-:*:*:*:*:*:*:*
Конфигурация 3Версия до 02 (исключая)
Одновременно
cpe:2.3:o:wago:762-3002_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:762-3002:-:*:*:*:*:*:*:*
Конфигурация 4Версия до 02 (исключая)
Одновременно
cpe:2.3:o:wago:762-3003_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:762-3003:-:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.20487
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.
EPSS
Процентиль: 95%
0.20487
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434