CVE-2022-4098: Wiesemann & Theis: Multiple products prone to missing authentication through spoofing

Published Dec 13, 2022
·
Updated

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

Affected Software

64 affected components
Wut Com-server \+\+ Firmware<1.55
Wut Com-server \+\+
Wut Com-server 20ma Firmware<1.55
Wut Com-server 20ma
Wut Com-server Highspeed 100basefx Firmware<1.78
Wut Com-server Highspeed 100basefx
Wut Com-server Highspeed 100baselx Firmware<1.78
Wut Com-server Highspeed 100baselx
Wut Com-server Highspeed 19\" 1port Firmware<1.78
Wut Com-server Highspeed 19\" 1port
Wut Com-server Highspeed 19\" 4port Firmware<1.78
Wut Com-server Highspeed 19\" 4port
Wut Com-server Highspeed Compact Firmware<1.78
Wut Com-server Highspeed Compact
Wut Com-server Highspeed Industry Firmware<1.78
Wut Com-server Highspeed Industry
Wut Com-server Highspeed Isolated Firmware<1.78
Wut Com-server Highspeed Isolated
Wut Com-server Highspeed Oem Firmware<1.78
Wut Com-server Highspeed Oem
Wut Com-server Highspeed Office 1port Firmware<1.78
Wut Com-server Highspeed Office 1port
Wut Com-server Highspeed Office 4port Firmware<1.78
Wut Com-server Highspeed Office 4port
Wut Com-server Highspeed Poe Firmware<1.78
Wut Com-server Highspeed Poe
Wut Com-server Highspeed Lc Firmware<1.55
Wut Com-server Highspeed Lc
Wut Com-server Highspeed Poe 3x Isolated Firmware<1.55
Wut Com-server Highspeed Poe 3x Isolated
Wut Com-server Highspeed Ul Firmware<1.55
Wut Com-server Highspeed Ul
All of the following
Wut Com-server \+\+ Firmware<1.55
Wut Com-server \+\+
All of the following
Wut Com-server 20ma Firmware<1.55
Wut Com-server 20ma
All of the following
Wut Com-server Highspeed 100basefx Firmware<1.78
Wut Com-server Highspeed 100basefx
All of the following
Wut Com-server Highspeed 100baselx Firmware<1.78
Wut Com-server Highspeed 100baselx
All of the following
Wut Com-server Highspeed 19\" 1port Firmware<1.78
Wut Com-server Highspeed 19\" 1port
All of the following
Wut Com-server Highspeed 19\" 4port Firmware<1.78
Wut Com-server Highspeed 19\" 4port
All of the following
Wut Com-server Highspeed Compact Firmware<1.78
Wut Com-server Highspeed Compact
All of the following
Wut Com-server Highspeed Industry Firmware<1.78
Wut Com-server Highspeed Industry
All of the following
Wut Com-server Highspeed Isolated Firmware<1.78
Wut Com-server Highspeed Isolated
All of the following
Wut Com-server Highspeed Oem Firmware<1.78
Wut Com-server Highspeed Oem
All of the following
Wut Com-server Highspeed Office 1port Firmware<1.78
Wut Com-server Highspeed Office 1port
All of the following
Wut Com-server Highspeed Office 4port Firmware<1.78
Wut Com-server Highspeed Office 4port
All of the following
Wut Com-server Highspeed Poe Firmware<1.78
Wut Com-server Highspeed Poe
All of the following
Wut Com-server Highspeed Lc Firmware<1.55
Wut Com-server Highspeed Lc
All of the following
Wut Com-server Highspeed Poe 3x Isolated Firmware<1.55
Wut Com-server Highspeed Poe 3x Isolated
All of the following
Wut Com-server Highspeed Ul Firmware<1.55
Wut Com-server Highspeed Ul

Event History

Dec 13, 2022
CVE Published
via MITRE·07:26 AM
Data Sourced
via MITRE·07:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2022-4098?

CVE-2022-4098 is a vulnerability in multiple Wiesemann&Theis products of the ComServer Series, which allows an attacker in the same subnet to bypass authentication through IP spoofing.

2

Which products are affected by CVE-2022-4098?

The Wut Com-server ++ Firmware versions up to 1.55 and the Wut Com-server 20ma Firmware versions up to 1.55 are affected.

3

How severe is CVE-2022-4098?

CVE-2022-4098 has a severity level of high with a CVSS score of 8.0.

4

How can an attacker exploit CVE-2022-4098?

An unauthenticated attacker in the same subnet can obtain the session ID of a logged-in user and change arbitrary settings by using IP spoofing.

5

Where can I find more information about CVE-2022-4098?

You can find more information about CVE-2022-4098 at the following link: [https://cert.vde.com/en/advisories/VDE-2022-057/](https://cert.vde.com/en/advisories/VDE-2022-057/)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203