First published: Mon Feb 27 2023(Updated: )
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wago 751-9301 Firmware | >=16<22 | |
Wago 751-9301 Firmware | =22 | |
Wago 751-9301 Firmware | =23 | |
Wago 751-9301 | ||
Wago 752-8303\/8000-002 Firmware | >=18<22 | |
Wago 752-8303\/8000-002 Firmware | =22 | |
Wago 752-8303\/8000-002 Firmware | =23 | |
Wago 752-8303\/8000-002 | ||
WAGO PFC100 Firmware | >=16<22 | |
WAGO PFC100 Firmware | =22 | |
WAGO PFC100 Firmware | =23 | |
WAGO PFC100 | ||
WAGO PFC200 Firmware | >=16<22 | |
WAGO PFC200 Firmware | =22 | |
WAGO PFC200 Firmware | =23 | |
WAGO PFC200 | ||
Wago Touch Panel 600 Advanced Firmware | >=16<22 | |
Wago Touch Panel 600 Advanced Firmware | =22 | |
Wago Touch Panel 600 Advanced Firmware | =23 | |
Wago Touch Panel 600 Advanced | ||
Wago Touch Panel 600 Marine Firmware | >=16<22 | |
Wago Touch Panel 600 Marine Firmware | =22 | |
Wago Touch Panel 600 Marine Firmware | =23 | |
Wago Touch Panel 600 Marine | ||
Wago Touch Panel 600 Standard Firmware | >=16<22 | |
Wago Touch Panel 600 Standard Firmware | =22 | |
Wago Touch Panel 600 Standard Firmware | =23 | |
Wago Touch Panel 600 Standard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-45137.
The severity of CVE-2022-45137 is medium. The severity value is 6.1.
The software products affected by CVE-2022-45137 include WAGO 751-9301 firmware versions 16 to 22, WAGO 752-8303/8000-002 firmware versions 18 to 22, WAGO PFC100 firmware versions 16 to 22, WAGO PFC200 firmware versions 16 to 22, Wago Touch Panel 600 Advanced firmware versions 16 to 22, Wago Touch Panel 600 Marine firmware versions 16 to 22, and Wago Touch Panel 600 Standard firmware versions 16 to 22.
CVE-2022-45137 has a limited impact on confidentiality and integrity, but no impact on availability.
You can find more information about CVE-2022-45137 at the following reference link: https://cert.vde.com/en/advisories/VDE-2022-060/