← Back

CVE-2022-45138

nvd nist
Published: Feb 27, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: info@cert.vde.com (Secondary)

Description

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.

Affected (21)

7 products
751 9301 Firmware
752 8303/8000 002 Firmware
Pfc100 Firmware
Pfc200 Firmware
Touch Panel 600 Advanced Firmware
Touch Panel 600 Marine Firmware
Touch Panel 600 Standard Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
751 9301
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 18 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
752 8303/8000 002
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
Pfc100
All versions
Configuration D
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
Pfc200
All versions
Configuration E
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
Touch Panel 600 Advanced
All versions
Configuration F
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
Touch Panel 600 Marine
All versions
Configuration G
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Wago
From 16 to 22
Version 22
Version 23
Running on/withPlatform Versions
Wago
Touch Panel 600 Standard
All versions

References (2)

Source: info@cert.vde.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.