First published: Mon Feb 27 2023(Updated: )
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wago 751-9301 Firmware | >=16<22 | |
Wago 751-9301 Firmware | =22 | |
Wago 751-9301 Firmware | =23 | |
Wago 751-9301 | ||
Wago 752-8303\/8000-002 Firmware | >=18<22 | |
Wago 752-8303\/8000-002 Firmware | =22 | |
Wago 752-8303\/8000-002 Firmware | =23 | |
Wago 752-8303\/8000-002 | ||
WAGO PFC100 Firmware | >=16<22 | |
WAGO PFC100 Firmware | =22 | |
WAGO PFC100 Firmware | =23 | |
WAGO PFC100 | ||
WAGO PFC200 Firmware | >=16<22 | |
WAGO PFC200 Firmware | =22 | |
WAGO PFC200 Firmware | =23 | |
WAGO PFC200 | ||
Wago Touch Panel 600 Advanced Firmware | >=16<22 | |
Wago Touch Panel 600 Advanced Firmware | =22 | |
Wago Touch Panel 600 Advanced Firmware | =23 | |
Wago Touch Panel 600 Advanced | ||
Wago Touch Panel 600 Marine Firmware | >=16<22 | |
Wago Touch Panel 600 Marine Firmware | =22 | |
Wago Touch Panel 600 Marine Firmware | =23 | |
Wago Touch Panel 600 Marine | ||
Wago Touch Panel 600 Standard Firmware | >=16<22 | |
Wago Touch Panel 600 Standard Firmware | =22 | |
Wago Touch Panel 600 Standard Firmware | =23 | |
Wago Touch Panel 600 Standard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45139 is a CORS misconfiguration vulnerability in the web-based management of certain WAGO devices.
The severity of CVE-2022-45139 is medium, with a severity value of 5.3.
CVE-2022-45139 allows a malicious third-party webserver to misuse all basic information pages on the affected WAGO devices.
CVE-2022-45139 can be exploited by a malicious third party by taking advantage of the CORS misconfiguration in the web-based management of the affected WAGO devices.
Yes, the vendor has released firmware updates to address the CORS misconfiguration vulnerability in the web-based management of the affected WAGO devices.