CVE-2023-5188
Last modified
CVE-2023-5188 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wago | Telecontrol Configurator | All versions |
| Wago | Wagoapprtu | < 1.4.6.0 |
References
- https://cert.vde.com/en/advisories/VDE-2023-044/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-044/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5188?
How severe is CVE-2023-5188?
How do I fix CVE-2023-5188?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-51842An algorithm-downgrade issue was discovered in Ylianst MeshC…7.5
- CVE-2023-51843react-dashboard 1.4.0 is vulnerable to Cross Site Scripting …8.2
- CVE-2023-51847An issue in obgm and Libcoap v.a3ed466 allows a remote attac…7.5
- CVE-2023-5185Gym Management System Project v1.0 is vulnerable to an Inse…8.8
- CVE-2023-5186Use after free in Passwords in Google Chrome prior to 117.0.…8.8
- CVE-2023-5187Use after free in Extensions in Google Chrome prior to 117.0…8.8
- CVE-2023-51885Buffer Overflow vulnerability in Mathtex v.1.05 and before a…9.8
- CVE-2023-51886Buffer Overflow vulnerability in the main() function in Math…7.5
- CVE-2023-51887Command Injection vulnerability in Mathtex v.1.05 and before…9.8
- CVE-2023-51888Buffer Overflow vulnerability in the nomath() function in Ma…7.5
- CVE-2023-51889Stack Overflow vulnerability in the validate() function in M…9.8
- CVE-2023-5189A path traversal vulnerability exists in Ansible when extrac…6.5
Are you affected by CVE-2023-5188?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
