CVE-2022-4098: Wiesemann & Theis: Multiple products prone to missing authentication through spoofing
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4098?
CVE-2022-4098 is a vulnerability in multiple Wiesemann&Theis products of the ComServer Series, which allows an attacker in the same subnet to bypass authentication through IP spoofing.
Which products are affected by CVE-2022-4098?
The Wut Com-server ++ Firmware versions up to 1.55 and the Wut Com-server 20ma Firmware versions up to 1.55 are affected.
How severe is CVE-2022-4098?
CVE-2022-4098 has a severity level of high with a CVSS score of 8.0.
How can an attacker exploit CVE-2022-4098?
An unauthenticated attacker in the same subnet can obtain the session ID of a logged-in user and change arbitrary settings by using IP spoofing.
Where can I find more information about CVE-2022-4098?
You can find more information about CVE-2022-4098 at the following link: [https://cert.vde.com/en/advisories/VDE-2022-057/](https://cert.vde.com/en/advisories/VDE-2022-057/)