CVE detail
CVE-2023-1698
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- The Convergence of Cloud Secrets & AI RiskSentinelOne Labs
initial access points. The top verified exploit paths continue to involve older, critical CVEs, including: Shellshock ( CVE-2014-6271 ) FortiGate SSL VPN credential disclosure ( CVE-2018-13379 ) Pulse Secure VPN arbitrary file read ( CVE-2019-11510 ) Webmin RCE ( CVE-2019-15107 ) Barracuda ESG zero-day backdoor ( CVE-2023-1698 ) Since these vulnerabil
vendorwww.sentinelone.comMay 13, 2026, 6:11 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-3379CVSS 5.3 · Medium
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escal…
- CVE-2023-4089CVSS 2.7 · Low
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This a…
- CVE-2022-3738CVSS 5.9 · Medium
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryp…
- CVE-2022-45140CVSS 9.8 · Critical
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and…
- CVE-2022-45139CVSS 5.3 · Medium
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-4…
- CVE-2022-45138CVSS 9.8 · Critical
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allo…