Lucene search

K
cve[email protected]CVE-2022-45139
HistoryFeb 27, 2023 - 3:15 p.m.

CVE-2022-45139

2023-02-2715:15:11
CWE-346
web.nvd.nist.gov
21
cors misconfiguration
cve-2022-45139
nvd
web-based management
disclosure of device information
cpu diagnostics

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.

Affected configurations

NVD
Node
wago751-9301_firmwareRange1622
OR
wago751-9301_firmwareMatch22-
OR
wago751-9301_firmwareMatch23
AND
wago751-9301Match-
Node
wago752-8303\/8000-002_firmwareRange1822
OR
wago752-8303\/8000-002_firmwareMatch22-
OR
wago752-8303\/8000-002_firmwareMatch23
AND
wago752-8303\/8000-002Match-
Node
wagopfc100_firmwareRange1622
OR
wagopfc100_firmwareMatch22-
OR
wagopfc100_firmwareMatch23
AND
wagopfc100Match-
Node
wagopfc200_firmwareRange1622
OR
wagopfc200_firmwareMatch22-
OR
wagopfc200_firmwareMatch23
AND
wagopfc200Match-
Node
wagotouch_panel_600_advanced_firmwareRange1622
OR
wagotouch_panel_600_advanced_firmwareMatch22-
OR
wagotouch_panel_600_advanced_firmwareMatch23
AND
wagotouch_panel_600_advancedMatch-
Node
wagotouch_panel_600_marine_firmwareRange1622
OR
wagotouch_panel_600_marine_firmwareMatch22-
OR
wagotouch_panel_600_marine_firmwareMatch23
AND
wagotouch_panel_600_marineMatch-
Node
wagotouch_panel_600_standard_firmwareRange1622
OR
wagotouch_panel_600_standard_firmwareMatch22-
OR
wagotouch_panel_600_standard_firmwareMatch23
AND
wagotouch_panel_600_standardMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Compact Controller CC100 (751-9301)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Edge Controller (752-8303/8000-002)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW18",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC100 (750-81xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC200 (750-82xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Advanced Line (762-5xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Marine Line (762-6xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Standard Line (762-4xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%

Related for CVE-2022-45139