Lucene search

K
cve[email protected]CVE-2022-45137
HistoryFeb 27, 2023 - 3:15 p.m.

CVE-2022-45137

2023-02-2715:15:11
CWE-79
web.nvd.nist.gov
18
cve-2022-45137
configuration backend
web-based management
reflected xss
cross-site scripting
nvd

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.3%

The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.

Affected configurations

NVD
Node
wago751-9301Match-
AND
wago751-9301_firmwareRange1622
OR
wago751-9301_firmwareMatch22-
OR
wago751-9301_firmwareMatch23
Node
wago752-8303\/8000-002Match-
AND
wago752-8303\/8000-002_firmwareRange1822
OR
wago752-8303\/8000-002_firmwareMatch22-
OR
wago752-8303\/8000-002_firmwareMatch23
Node
wagopfc100Match-
AND
wagopfc100_firmwareRange1622
OR
wagopfc100_firmwareMatch22-
OR
wagopfc100_firmwareMatch23
Node
wagopfc200Match-
AND
wagopfc200_firmwareRange1622
OR
wagopfc200_firmwareMatch22-
OR
wagopfc200_firmwareMatch23
Node
wagotouch_panel_600_advancedMatch-
AND
wagotouch_panel_600_advanced_firmwareRange1622
OR
wagotouch_panel_600_advanced_firmwareMatch22-
OR
wagotouch_panel_600_advanced_firmwareMatch23
Node
wagotouch_panel_600_marineMatch-
AND
wagotouch_panel_600_marine_firmwareRange1622
OR
wagotouch_panel_600_marine_firmwareMatch22-
OR
wagotouch_panel_600_marine_firmwareMatch23
Node
wagotouch_panel_600_standardMatch-
AND
wagotouch_panel_600_standard_firmwareRange1622
OR
wagotouch_panel_600_standard_firmwareMatch22-
OR
wagotouch_panel_600_standard_firmwareMatch23

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Compact Controller CC100 (751-9301)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Edge Controller (752-8303/8000-002)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW18",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC100 (750-81xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC200 (750-82xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Advanced Line (762-5xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Marine Line (762-6xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Standard Line (762-4xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.3%

Related for CVE-2022-45137