CVE-2022-45138
WAGO: Missing Authentication for Critical Function
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
*Credits:
Ryan Pickren of Georgia Institute of Technologys Cyber-Physical Security Lab
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-11-10 CVE Reserved
- 2023-02-27 CVE Published
- 2024-08-03 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
- CAPEC-115: Authentication Bypass
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2022-060 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wago Search vendor "Wago" | 751-9301 Firmware Search vendor "Wago" for product "751-9301 Firmware" | >= 16 < 22 Search vendor "Wago" for product "751-9301 Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | 751-9301 Search vendor "Wago" for product "751-9301" | - | - |
Safe
|
Wago Search vendor "Wago" | 751-9301 Firmware Search vendor "Wago" for product "751-9301 Firmware" | 22 Search vendor "Wago" for product "751-9301 Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | 751-9301 Search vendor "Wago" for product "751-9301" | - | - |
Safe
|
Wago Search vendor "Wago" | 751-9301 Firmware Search vendor "Wago" for product "751-9301 Firmware" | 23 Search vendor "Wago" for product "751-9301 Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | 751-9301 Search vendor "Wago" for product "751-9301" | - | - |
Safe
|
Wago Search vendor "Wago" | 752-8303\/8000-002 Firmware Search vendor "Wago" for product "752-8303\/8000-002 Firmware" | >= 18 < 22 Search vendor "Wago" for product "752-8303\/8000-002 Firmware" and version " >= 18 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | 752-8303\/8000-002 Search vendor "Wago" for product "752-8303\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 752-8303\/8000-002 Firmware Search vendor "Wago" for product "752-8303\/8000-002 Firmware" | 22 Search vendor "Wago" for product "752-8303\/8000-002 Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | 752-8303\/8000-002 Search vendor "Wago" for product "752-8303\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | 752-8303\/8000-002 Firmware Search vendor "Wago" for product "752-8303\/8000-002 Firmware" | 23 Search vendor "Wago" for product "752-8303\/8000-002 Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | 752-8303\/8000-002 Search vendor "Wago" for product "752-8303\/8000-002" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc100 Firmware Search vendor "Wago" for product "Pfc100 Firmware" | >= 16 < 22 Search vendor "Wago" for product "Pfc100 Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc100 Search vendor "Wago" for product "Pfc100" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc100 Firmware Search vendor "Wago" for product "Pfc100 Firmware" | 22 Search vendor "Wago" for product "Pfc100 Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc100 Search vendor "Wago" for product "Pfc100" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc100 Firmware Search vendor "Wago" for product "Pfc100 Firmware" | 23 Search vendor "Wago" for product "Pfc100 Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc100 Search vendor "Wago" for product "Pfc100" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc200 Firmware Search vendor "Wago" for product "Pfc200 Firmware" | >= 16 < 22 Search vendor "Wago" for product "Pfc200 Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc200 Search vendor "Wago" for product "Pfc200" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc200 Firmware Search vendor "Wago" for product "Pfc200 Firmware" | 22 Search vendor "Wago" for product "Pfc200 Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc200 Search vendor "Wago" for product "Pfc200" | - | - |
Safe
|
Wago Search vendor "Wago" | Pfc200 Firmware Search vendor "Wago" for product "Pfc200 Firmware" | 23 Search vendor "Wago" for product "Pfc200 Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | Pfc200 Search vendor "Wago" for product "Pfc200" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Advanced Firmware Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" | >= 16 < 22 Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Advanced Search vendor "Wago" for product "Touch Panel 600 Advanced" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Advanced Firmware Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" | 22 Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Advanced Search vendor "Wago" for product "Touch Panel 600 Advanced" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Advanced Firmware Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" | 23 Search vendor "Wago" for product "Touch Panel 600 Advanced Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Advanced Search vendor "Wago" for product "Touch Panel 600 Advanced" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Marine Firmware Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" | >= 16 < 22 Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Marine Search vendor "Wago" for product "Touch Panel 600 Marine" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Marine Firmware Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" | 22 Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Marine Search vendor "Wago" for product "Touch Panel 600 Marine" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Marine Firmware Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" | 23 Search vendor "Wago" for product "Touch Panel 600 Marine Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Marine Search vendor "Wago" for product "Touch Panel 600 Marine" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Standard Firmware Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" | >= 16 < 22 Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" and version " >= 16 < 22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Standard Search vendor "Wago" for product "Touch Panel 600 Standard" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Standard Firmware Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" | 22 Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" and version "22" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Standard Search vendor "Wago" for product "Touch Panel 600 Standard" | - | - |
Safe
|
Wago Search vendor "Wago" | Touch Panel 600 Standard Firmware Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" | 23 Search vendor "Wago" for product "Touch Panel 600 Standard Firmware" and version "23" | - |
Affected
| in | Wago Search vendor "Wago" | Touch Panel 600 Standard Search vendor "Wago" for product "Touch Panel 600 Standard" | - | - |
Safe
|