cbcvebase.
CVE-2022-3738
published 2023-01-19

CVE-2022-3738: The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like…

PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.63%
45.8th percentile
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

Affected

14 ranges
VendorProductVersion rangeFixed in
wagocc100_firmware16 – 22
wagoedge_controller_firmware16 – 22
wagopfc100_firmware16 – 22
wagopfc200_firmware16 – 22
wagoseries_wago_pfc100FW16 – FW22
wagoseries_wago_pfc200FW16 – FW22
wagoseries_wago_touch_panel_600_advanced_lineFW16 – FW22
wagoseries_wago_touch_panel_600_marine_lineFW16 – FW22
wagoseries_wago_touch_panel_600_standard_lineFW16 – FW22
wagotouch_panel_600_advanced_firmware16 – 22
wagotouch_panel_600_marine_firmware16 – 22
wagotouch_panel_600_standard_firmware16 – 22
wagowago_compact_controller_cc100FW16 – FW22
wagowago_edge_controllerFW16 – FW22
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.