CVE-2022-45139

CVSS V2 None CVSS V3 None
Description
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Overview
  • CVE ID
  • CVE-2022-45139
  • Assigner
  • info@cert.vde.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-27T15:15:11
  • Last Modified Date
  • 2023-03-07T22:54:57
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:wago:751-9301_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:751-9301_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:751-9301_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:751-9301:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:752-8303\/8000-002_firmware:*:*:*:*:*:*:*:* 1 OR 18 22
cpe:2.3:o:wago:752-8303\/8000-002_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:752-8303\/8000-002_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:752-8303\/8000-002:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:pfc100_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:pfc100_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:pfc200_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:pfc200_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:touch_panel_600_marine_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:* 1 OR 16 22
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:wago:touch_panel_600_standard_firmware:23:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:* 0 OR
References
Reference URL Reference Tags
https://cert.vde.com/en/advisories/VDE-2022-060/ Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 05:29:35 Added to TrackCVE
2023-04-17 05:29:38 Weakness Enumeration new