2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-45139" ,
"sourceIdentifier" : "info@cert.vde.com" ,
"published" : "2023-02-27T15:15:11.407" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:28:50.013" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "info@cert.vde.com" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "info@cert.vde.com" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-346"
}
]
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-346"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:751-9301_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "D694685C-2D87-4C94-9957-6B921E8836CF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:751-9301_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "E42B14D3-F36A-4213-8447-870E9FC60F48"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:751-9301_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "84839593-47AD-47C1-8762-FAF10070BCAD"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:751-9301:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "385FE0DA-6383-4EF7-835A-055EB0D22EB8"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:752-8303\\/8000-002_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "18" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "4958E9ED-6410-4F34-B582-7532A7F3101C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:752-8303\\/8000-002_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4761AA7-B270-485C-B929-34384145DCBB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:752-8303\\/8000-002_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B514966-03EE-4710-89C0-E8FE771E79CD"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:752-8303\\/8000-002:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "915B0745-EB00-40AD-80BA-887EFB435901"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "D0044A0A-90FD-4C5E-B1F9-A7A0B9EF0BE8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "4815DFF8-0CAE-4C85-9F5B-F64C12F43AB0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc100_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2C84D09E-A681-47F1-AC37-850BF6E47D01"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F636354-95A2-4B36-9666-1FA57F185432"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "EEF2D886-205E-46D2-80DA-2E594F867EE5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "B876DC19-0523-41DB-8BD7-1ECC09FCFA01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:pfc200_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE108CD0-B451-4ED5-83A1-CCEAACC1B40C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "688A3248-7EAA-499D-A47C-A4D4900CDBD1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "FE5248EE-90DF-446C-BC44-D5AF5EDB45A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "9A613D7C-29C0-4D4E-ACDA-15BBC6FF0104"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D06AC6E-2EB2-4ACB-A6CA-E7AB88540713"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A8221861-7455-41D5-B310-6AEA822B46CF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "0FF35303-B999-40FE-8DC1-C18243F13FE7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "774CFF47-61B6-48F8-8E1F-E3DC215066AF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_marine_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD092B48-C42A-409E-AC9C-F523AD654C1B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "83DEFFBC-934D-43BE-92AE-25F8EE8C1E0A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "16" ,
"versionEndExcluding" : "22" ,
"matchCriteriaId" : "9B8C054D-F02F-48A0-85D0-DFF90E9C31BB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "FA7A911A-395A-4536-8756-83DB2F62899D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wago:touch_panel_600_standard_firmware:23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "263C0C64-F5B4-43C3-BF26-AF24DFA74699"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6D7A44C-2D95-4F69-A7DB-435B0A6F9F03"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://cert.vde.com/en/advisories/VDE-2022-060/" ,
"source" : "info@cert.vde.com" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert.vde.com/en/advisories/VDE-2022-060/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}