First published: Mon Feb 27 2023(Updated: )
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wago 751-9301 Firmware | >=16<22 | |
Wago 751-9301 Firmware | =22 | |
Wago 751-9301 Firmware | =23 | |
Wago 751-9301 | ||
Wago 752-8303\/8000-002 Firmware | >=18<22 | |
Wago 752-8303\/8000-002 Firmware | =22 | |
Wago 752-8303\/8000-002 Firmware | =23 | |
Wago 752-8303\/8000-002 | ||
WAGO PFC100 Firmware | >=16<22 | |
WAGO PFC100 Firmware | =22 | |
WAGO PFC100 Firmware | =23 | |
WAGO PFC100 | ||
WAGO PFC200 Firmware | >=16<22 | |
WAGO PFC200 Firmware | =22 | |
WAGO PFC200 Firmware | =23 | |
WAGO PFC200 | ||
Wago Touch Panel 600 Advanced Firmware | >=16<22 | |
Wago Touch Panel 600 Advanced Firmware | =22 | |
Wago Touch Panel 600 Advanced Firmware | =23 | |
Wago Touch Panel 600 Advanced | ||
Wago Touch Panel 600 Marine Firmware | >=16<22 | |
Wago Touch Panel 600 Marine Firmware | =22 | |
Wago Touch Panel 600 Marine Firmware | =23 | |
Wago Touch Panel 600 Marine | ||
Wago Touch Panel 600 Standard Firmware | >=16<22 | |
Wago Touch Panel 600 Standard Firmware | =22 | |
Wago Touch Panel 600 Standard Firmware | =23 | |
Wago Touch Panel 600 Standard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45140 is critical with a severity value of 9.8.
CVE-2022-45140 allows an unauthenticated user to write arbitrary data with root privileges, potentially leading to unauthenticated remote code execution and full system compromise on affected WAGO devices.
CVE-2022-45140 affects WAGO devices including 751-9301 firmware versions 16 to 22, 752-8303/8000-002 firmware versions 18 to 22, and PFC100, PFC200, Touch Panel 600 Advanced, Touch Panel 600 Marine, and Touch Panel 600 Standard firmware versions 16 to 22.
To fix CVE-2022-45140, it is recommended to update the firmware of the affected WAGO devices to a version that is not vulnerable.
More information about CVE-2022-45140 can be found at the following link: [https://cert.vde.com/en/advisories/VDE-2022-060/](https://cert.vde.com/en/advisories/VDE-2022-060/)