cbcvebase.
CVE-2022-45138
published 2023-02-27

CVE-2022-45138: The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
wago751-9301_firmware
wago751-9301_firmware
wago751-9301_firmware>= 16 < 2222
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware>= 18 < 2222
wagocompact_controller_cc100
wagocompact_controller_cc100>= FW16 < FW22FW22
wagoedge_controller
wagoedge_controller>= FW18 < FW22FW22
wagopfc100
wagopfc100>= FW16 < FW22FW22
wagopfc100_firmware
wagopfc100_firmware
wagopfc100_firmware>= 16 < 2222
wagopfc200
wagopfc200>= FW16 < FW22FW22
wagopfc200_firmware
wagopfc200_firmware
wagopfc200_firmware>= 16 < 2222
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware>= 16 < 2222
wagotouch_panel_600_advanced_line
wagotouch_panel_600_advanced_line>= FW16 < FW22FW22