Lucene search

K
cve[email protected]CVE-2022-45140
HistoryFeb 27, 2023 - 3:15 p.m.

CVE-2022-45140

2023-02-2715:15:11
CWE-306
web.nvd.nist.gov
36
cve-2022-45140
configuration backend
unauthenticated user
remote code execution
system compromise

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.8%

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

Affected configurations

NVD
Node
wago751-9301_firmwareRange1622
OR
wago751-9301_firmwareMatch22-
OR
wago751-9301_firmwareMatch23
AND
wago751-9301Match-
Node
wago752-8303\/8000-002_firmwareRange1822
OR
wago752-8303\/8000-002_firmwareMatch22-
OR
wago752-8303\/8000-002_firmwareMatch23
AND
wago752-8303\/8000-002Match-
Node
wagopfc100_firmwareRange1622
OR
wagopfc100_firmwareMatch22-
OR
wagopfc100_firmwareMatch23
AND
wagopfc100Match-
Node
wagopfc200_firmwareRange1622
OR
wagopfc200_firmwareMatch22-
OR
wagopfc200_firmwareMatch23
AND
wagopfc200Match-
Node
wagotouch_panel_600_advanced_firmwareRange1622
OR
wagotouch_panel_600_advanced_firmwareMatch22-
OR
wagotouch_panel_600_advanced_firmwareMatch23
AND
wagotouch_panel_600_advancedMatch-
Node
wagotouch_panel_600_marine_firmwareRange1622
OR
wagotouch_panel_600_marine_firmwareMatch22-
OR
wagotouch_panel_600_marine_firmwareMatch23
AND
wagotouch_panel_600_marineMatch-
Node
wagotouch_panel_600_standard_firmwareRange1622
OR
wagotouch_panel_600_standard_firmwareMatch22-
OR
wagotouch_panel_600_standard_firmwareMatch23
AND
wagotouch_panel_600_standardMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Compact Controller CC100 (751-9301)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Edge Controller (752-8303/8000-002)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC100 (750-81xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "PFC200 (750-82xx/xxx-xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Advanced Line (762-5xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Marine Line (762-6xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Touch Panel 600 Standard Line (762-4xxx)",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "FW22",
        "status": "affected",
        "version": "FW16",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FW22 Patch 1"
      },
      {
        "status": "affected",
        "version": "FW23"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.8%

Related for CVE-2022-45140