CVE-2022-45138
Summary
| CVE | CVE-2022-45138 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-27 15:15:00 UTC |
| Updated | 2023-03-07 22:54:00 UTC |
| Description | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Wago | 751-9301 | - | All | All | All |
| Operating System | Wago | 751-9301 Firmware | All | All | All | All |
| Operating System | Wago | 751-9301 Firmware | 22 | - | All | All |
| Operating System | Wago | 751-9301 Firmware | 23 | All | All | All |
| Hardware | Wago | 752-8303/8000-002 | - | All | All | All |
| Operating System | Wago | 752-8303/8000-002 Firmware | All | All | All | All |
| Operating System | Wago | 752-8303/8000-002 Firmware | 22 | - | All | All |
| Operating System | Wago | 752-8303/8000-002 Firmware | 23 | All | All | All |
| Hardware | Wago | Pfc100 | - | All | All | All |
| Operating System | Wago | Pfc100 Firmware | All | All | All | All |
| Operating System | Wago | Pfc100 Firmware | 22 | - | All | All |
| Operating System | Wago | Pfc100 Firmware | 23 | All | All | All |
| Hardware | Wago | Pfc200 | - | All | All | All |
| Operating System | Wago | Pfc200 Firmware | All | All | All | All |
| Operating System | Wago | Pfc200 Firmware | 22 | - | All | All |
| Operating System | Wago | Pfc200 Firmware | 23 | All | All | All |
| Hardware | Wago | Touch Panel 600 Advanced | - | All | All | All |
| Operating System | Wago | Touch Panel 600 Advanced Firmware | All | All | All | All |
| Operating System | Wago | Touch Panel 600 Advanced Firmware | 22 | - | All | All |
| Operating System | Wago | Touch Panel 600 Advanced Firmware | 23 | All | All | All |
| Hardware | Wago | Touch Panel 600 Marine | - | All | All | All |
| Operating System | Wago | Touch Panel 600 Marine Firmware | All | All | All | All |
| Operating System | Wago | Touch Panel 600 Marine Firmware | 22 | - | All | All |
| Operating System | Wago | Touch Panel 600 Marine Firmware | 23 | All | All | All |
| Hardware | Wago | Touch Panel 600 Standard | - | All | All | All |
| Operating System | Wago | Touch Panel 600 Standard Firmware | All | All | All | All |
| Operating System | Wago | Touch Panel 600 Standard Firmware | 22 | - | All | All |
| Operating System | Wago | Touch Panel 600 Standard Firmware | 23 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VDE-2022-060 | CERT@VDE | MISC | cert.vde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.