CVE-2022-3738
published 2023-01-19CVE-2022-3738: The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.63%
45.8th percentile
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | cc100_firmware | 16 – 22 | — |
| wago | edge_controller_firmware | 16 – 22 | — |
| wago | pfc100_firmware | 16 – 22 | — |
| wago | pfc200_firmware | 16 – 22 | — |
| wago | series_wago_pfc100 | FW16 – FW22 | — |
| wago | series_wago_pfc200 | FW16 – FW22 | — |
| wago | series_wago_touch_panel_600_advanced_line | FW16 – FW22 | — |
| wago | series_wago_touch_panel_600_marine_line | FW16 – FW22 | — |
| wago | series_wago_touch_panel_600_standard_line | FW16 – FW22 | — |
| wago | touch_panel_600_advanced_firmware | 16 – 22 | — |
| wago | touch_panel_600_marine_firmware | 16 – 22 | — |
| wago | touch_panel_600_standard_firmware | 16 – 22 | — |
| wago | wago_compact_controller_cc100 | FW16 – FW22 | — |
| wago | wago_edge_controller | FW16 – FW22 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-19
Published