CVE-2022-45137: WAGO: Reflective Cross-Site Scripting
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45137.
What is the severity of CVE-2022-45137?
The severity of CVE-2022-45137 is medium. The severity value is 6.1.
Which software products are affected by CVE-2022-45137?
The software products affected by CVE-2022-45137 include WAGO 751-9301 firmware versions 16 to 22, WAGO 752-8303/8000-002 firmware versions 18 to 22, WAGO PFC100 firmware versions 16 to 22, WAGO PFC200 firmware versions 16 to 22, Wago Touch Panel 600 Advanced firmware versions 16 to 22, Wago Touch Panel 600 Marine firmware versions 16 to 22, and Wago Touch Panel 600 Standard firmware versions 16 to 22.
What is the impact of CVE-2022-45137?
CVE-2022-45137 has a limited impact on confidentiality and integrity, but no impact on availability.
Where can I find more information about CVE-2022-45137?
You can find more information about CVE-2022-45137 at the following reference link: https://cert.vde.com/en/advisories/VDE-2022-060/