CVE-2022-45140
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Affected (21)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago 751 9301 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 18 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago 752 8303/8000 002 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Pfc200 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Advanced | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Marine | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 16 to 22 |
| Running on/with | Platform Versions |
|---|---|
Wago Touch Panel 600 Standard | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.