CVE-2022-45138
published 2023-02-27CVE-2022-45138: The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.74%
50.3th percentile
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wago | 751-9301_firmware | — | — |
| wago | 751-9301_firmware | — | — |
| wago | 751-9301_firmware | >= 16 < 22 | 22 |
| wago | 752-8303_8000-002_firmware | — | — |
| wago | 752-8303_8000-002_firmware | — | — |
| wago | 752-8303_8000-002_firmware | >= 18 < 22 | 22 |
| wago | compact_controller_cc100 | — | — |
| wago | compact_controller_cc100 | >= FW16 < FW22 | FW22 |
| wago | edge_controller | — | — |
| wago | edge_controller | >= FW18 < FW22 | FW22 |
| wago | pfc100 | — | — |
| wago | pfc100 | >= FW16 < FW22 | FW22 |
| wago | pfc100_firmware | — | — |
| wago | pfc100_firmware | — | — |
| wago | pfc100_firmware | >= 16 < 22 | 22 |
| wago | pfc200 | — | — |
| wago | pfc200 | >= FW16 < FW22 | FW22 |
| wago | pfc200_firmware | — | — |
| wago | pfc200_firmware | — | — |
| wago | pfc200_firmware | >= 16 < 22 | 22 |
| wago | touch_panel_600_advanced_firmware | — | — |
| wago | touch_panel_600_advanced_firmware | — | — |
| wago | touch_panel_600_advanced_firmware | >= 16 < 22 | 22 |
| wago | touch_panel_600_advanced_line | — | — |
| wago | touch_panel_600_advanced_line | >= FW16 < FW22 | FW22 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hq37-597p-8qrg: The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use th
ghsa_unreviewed·2023-02-27
CVE-2022-45138 [CRITICAL] CWE-306 GHSA-hq37-597p-8qrg: The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use th
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
GHSA
GHSA-p586-5mqw-6f9x: A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver
ghsa_unreviewed·2023-02-27·CVSS 9.8
CVE-2022-45139 [CRITICAL] CWE-346 GHSA-p586-5mqw-6f9x: A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published