CVE-2022-45139: WAGO: Origin validation error through CORS misconfiguration
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45139?
CVE-2022-45139 is a CORS misconfiguration vulnerability in the web-based management of certain WAGO devices.
What is the severity of CVE-2022-45139?
The severity of CVE-2022-45139 is medium, with a severity value of 5.3.
How does CVE-2022-45139 affect WAGO devices?
CVE-2022-45139 allows a malicious third-party webserver to misuse all basic information pages on the affected WAGO devices.
How can CVE-2022-45139 be exploited?
CVE-2022-45139 can be exploited by a malicious third party by taking advantage of the CORS misconfiguration in the web-based management of the affected WAGO devices.
Is there a fix for CVE-2022-45139?
Yes, the vendor has released firmware updates to address the CORS misconfiguration vulnerability in the web-based management of the affected WAGO devices.