A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wago
Subscribe
|
751-9301
Subscribe
751-9301 Firmware
Subscribe
752-8303\/8000-002
Subscribe
752-8303\/8000-002 Firmware
Subscribe
Pfc100
Subscribe
Pfc100 Firmware
Subscribe
Pfc200
Subscribe
Pfc200 Firmware
Subscribe
Touch Panel 600 Advanced
Subscribe
Touch Panel 600 Advanced Firmware
Subscribe
Touch Panel 600 Marine
Subscribe
Touch Panel 600 Marine Firmware
Subscribe
Touch Panel 600 Standard
Subscribe
Touch Panel 600 Standard Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48054 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-060/ |
|
History
Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-03-10T17:46:16.888Z
Reserved: 2022-11-10T09:46:59.080Z
Link: CVE-2022-45139
Updated: 2024-08-03T14:09:55.406Z
Status : Modified
Published: 2023-02-27T15:15:11.407
Modified: 2024-11-21T07:28:50.013
Link: CVE-2022-45139
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD