CVE-2022-3738

Severity
5.9MEDIUM
EPSS
0.3%
top 46.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19

Description

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages14 packages

NVDwago/cc100_firmware1622
NVDwago/pfc100_firmware1622
NVDwago/pfc200_firmware1622
CVEListV5wago/series_wago_pfc100FW16FW22
CVEListV5wago/series_wago_pfc200FW16FW22

🔴Vulnerability Details

2
CVEList
WAGO: Missing authentication for config export functionality in multiple products2023-01-19
GHSA
GHSA-r52m-fm69-5vrj: The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists2023-01-19