CVE-2022-22511
WAGO PLCs WBM vulnerable to reflected XSS
Severity Score
5.4
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
Varias páginas de configuración del dispositivo son vulnerables a ataques de tipo XSS (Cross-Site Scripting) reflejados. Un atacante autorizado con privilegios de usuario puede usar esto para conseguir acceso a información confidencial en un PC que sea conectado al WBM después de haber sido comprometido
*Credits:
These vulnerabilities were reported to WAGO by: Mohamed Magdy Abumuslim, coordination done by CERT@VDE.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-01-03 CVE Reserved
- 2022-03-09 CVE Published
- 2023-09-30 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2022-004 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wago Search vendor "Wago" | 750-8100 Firmware Search vendor "Wago" for product "750-8100 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8100 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8100 Search vendor "Wago" for product "750-8100" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8101 Firmware Search vendor "Wago" for product "750-8101 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8101 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8101 Search vendor "Wago" for product "750-8101" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8102 Firmware Search vendor "Wago" for product "750-8102 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8102 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8102 Search vendor "Wago" for product "750-8102" | - | - |
Safe
|
Wago Search vendor "Wago" | 751-9301 Firmware Search vendor "Wago" for product "751-9301 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "751-9301 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 751-9301 Search vendor "Wago" for product "751-9301" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8202 Firmware Search vendor "Wago" for product "750-8202 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8202 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8202 Search vendor "Wago" for product "750-8202" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-4205\/8000-002 Firmware Search vendor "Wago" for product "762-4205\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-4205\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-4205\/8000-002 Search vendor "Wago" for product "762-4205\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-4206\/8000-002 Firmware Search vendor "Wago" for product "762-4206\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-4206\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-4206\/8000-002 Search vendor "Wago" for product "762-4206\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-4305\/8000-002 Firmware Search vendor "Wago" for product "762-4305\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-4305\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-4305\/8000-002 Search vendor "Wago" for product "762-4305\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-4306\/8000-002 Firmware Search vendor "Wago" for product "762-4306\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-4306\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-4306\/8000-002 Search vendor "Wago" for product "762-4306\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-5205\/8000-001 Firmware Search vendor "Wago" for product "762-5205\/8000-001 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-5205\/8000-001 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-5205\/8000-001 Search vendor "Wago" for product "762-5205\/8000-001" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-5206\/8000-001 Firmware Search vendor "Wago" for product "762-5206\/8000-001 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-5206\/8000-001 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-5206\/8000-001 Search vendor "Wago" for product "762-5206\/8000-001" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-5305\/8000-002 Firmware Search vendor "Wago" for product "762-5305\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-5305\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-5305\/8000-002 Search vendor "Wago" for product "762-5305\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-5306\/8000-002 Firmware Search vendor "Wago" for product "762-5306\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-5306\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-5306\/8000-002 Search vendor "Wago" for product "762-5306\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-6301\/8000-002 Firmware Search vendor "Wago" for product "762-6301\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-6301\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-6301\/8000-002 Search vendor "Wago" for product "762-6301\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-6302\/8000-002 Firmware Search vendor "Wago" for product "762-6302\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-6302\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-6302\/8000-002 Search vendor "Wago" for product "762-6302\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-6303\/8000-002 Firmware Search vendor "Wago" for product "762-6303\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-6303\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-6303\/8000-002 Search vendor "Wago" for product "762-6303\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 762-6304\/8000-002 Firmware Search vendor "Wago" for product "762-6304\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "762-6304\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 762-6304\/8000-002 Search vendor "Wago" for product "762-6304\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8102\/025-000 Firmware Search vendor "Wago" for product "750-8102\/025-000 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8102\/025-000 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8102\/025-000 Search vendor "Wago" for product "750-8102\/025-000" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8101\/025-000 Firmware Search vendor "Wago" for product "750-8101\/025-000 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8101\/025-000 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8102\/025-000 Search vendor "Wago" for product "750-8102\/025-000" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-82 Firmware Search vendor "Wago" for product "750-82 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-82 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-82 Search vendor "Wago" for product "750-82" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8202\/000-012 Firmware Search vendor "Wago" for product "750-8202\/000-012 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8202\/000-012 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8202\/000-012 Search vendor "Wago" for product "750-8202\/000-012" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8202\/000-022 Firmware Search vendor "Wago" for product "750-8202\/000-022 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8202\/000-022 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8202\/000-022 Search vendor "Wago" for product "750-8202\/000-022" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8202\/025-001 Firmware Search vendor "Wago" for product "750-8202\/025-001 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8202\/025-001 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8202\/025-001 Search vendor "Wago" for product "750-8202\/025-001" | - | - |
Safe
|
Wago Search vendor "Wago" | 750-8202\/025-000 Firmware Search vendor "Wago" for product "750-8202\/025-000 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "750-8202\/025-000 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 750-8202\/025-000 Search vendor "Wago" for product "750-8202\/025-000" | - | - |
Safe
|
Wago Search vendor "Wago" | 752-8303\/8000-002 Firmware Search vendor "Wago" for product "752-8303\/8000-002 Firmware" | >= fw16 < fw22 Search vendor "Wago" for product "752-8303\/8000-002 Firmware" and version " >= fw16 < fw22" | - |
Affected
| in | Wago Search vendor "Wago" | 752-8303\/8000-002 Search vendor "Wago" for product "752-8303\/8000-002" | - | - |
Safe
|