Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact None
User Interaction Required
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00074.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Wago
Subscribe
|
750-8100
Subscribe
750-8100 Firmware
Subscribe
750-8101
Subscribe
750-8101\/025-000 Firmware
Subscribe
750-8101 Firmware
Subscribe
750-8102
Subscribe
750-8102\/025-000
Subscribe
750-8102\/025-000 Firmware
Subscribe
750-8102 Firmware
Subscribe
750-82
Subscribe
750-8202
Subscribe
750-8202\/000-012
Subscribe
750-8202\/000-012 Firmware
Subscribe
750-8202\/000-022
Subscribe
750-8202\/000-022 Firmware
Subscribe
750-8202\/025-000
Subscribe
750-8202\/025-000 Firmware
Subscribe
750-8202\/025-001
Subscribe
750-8202\/025-001 Firmware
Subscribe
750-8202 Firmware
Subscribe
750-82 Firmware
Subscribe
751-9301
Subscribe
751-9301 Firmware
Subscribe
752-8303\/8000-002
Subscribe
752-8303\/8000-002 Firmware
Subscribe
762-4205\/8000-002
Subscribe
762-4205\/8000-002 Firmware
Subscribe
762-4206\/8000-002
Subscribe
762-4206\/8000-002 Firmware
Subscribe
762-4305\/8000-002
Subscribe
762-4305\/8000-002 Firmware
Subscribe
762-4306\/8000-002
Subscribe
762-4306\/8000-002 Firmware
Subscribe
762-5205\/8000-001
Subscribe
762-5205\/8000-001 Firmware
Subscribe
762-5206\/8000-001
Subscribe
762-5206\/8000-001 Firmware
Subscribe
762-5305\/8000-002
Subscribe
762-5305\/8000-002 Firmware
Subscribe
762-5306\/8000-002
Subscribe
762-5306\/8000-002 Firmware
Subscribe
762-6301\/8000-002
Subscribe
762-6301\/8000-002 Firmware
Subscribe
762-6302\/8000-002
Subscribe
762-6302\/8000-002 Firmware
Subscribe
762-6303\/8000-002
Subscribe
762-6303\/8000-002 Firmware
Subscribe
762-6304\/8000-002
Subscribe
762-6304\/8000-002 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27657 | Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised. |
Solution
Install FW >=FW22 (FW22 planned for end of Q2/22)
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-004/ |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-17T00:16:00.059Z
Reserved: 2022-01-03T00:00:00
Link: CVE-2022-22511
No data.
Status : Modified
Published: 2022-03-09T20:15:08.367
Modified: 2024-11-21T06:46:55.623
Link: CVE-2022-22511
No data.
OpenCVE Enrichment
No data.
EUVD