Article No° | Product Name | Affected Version(s) |
---|---|---|
Smart Designer | <= 2.33.1 |
An attacker with privileges can enumerate projects and usernames through an iterative process, by making a request to a specific endpoint.
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
The vulnerability might result in disclosure of sensitive information.
Remediation
A patch for the WAGO Smart Designer will be available with version 2.34.
The vulnerability was reported by Brett Dewall from White Oak Security.
Coordination done by CERT@VDE.