CVE-2022-22511: WAGO PLCs WBM vulnerable to reflected XSS
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22511?
CVE-2022-22511 is a vulnerability affecting various configuration pages of the Wago device, making them vulnerable to reflected XSS (Cross-Site Scripting) attacks.
How can an attacker exploit CVE-2022-22511?
An authorized attacker with user privileges can exploit CVE-2022-22511 to gain access to confidential information on a compromised PC that connects to the Wago Web-Based Management (WBM) interface.
What is the severity of CVE-2022-22511?
CVE-2022-22511 has a severity rating of medium (5.4) according to the Common Vulnerability Scoring System (CVSS) v3.0.
Which Wago devices are affected by CVE-2022-22511?
Various Wago devices running firmware versions between fw16 and fw22 are affected by CVE-2022-22511.
Where can I find more information about CVE-2022-22511?
You can find more information about CVE-2022-22511 in the advisory published by VDE-CERT.