Vulnerability Details CVE-2022-4098
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.0%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2022-4098
-
cpe:2.3:h:wut:com-server_++:-
-
cpe:2.3:h:wut:com-server_20ma:-
-
cpe:2.3:h:wut:com-server_highspeed_100basefx:-
-
cpe:2.3:h:wut:com-server_highspeed_100baselx:-
-
cpe:2.3:h:wut:com-server_highspeed_19"_1port:-
-
cpe:2.3:h:wut:com-server_highspeed_19"_4port:-
-
cpe:2.3:h:wut:com-server_highspeed_compact:-
-
cpe:2.3:h:wut:com-server_highspeed_industry:-
-
cpe:2.3:h:wut:com-server_highspeed_isolated:-
-
cpe:2.3:h:wut:com-server_highspeed_lc:-
-
cpe:2.3:h:wut:com-server_highspeed_oem:-
-
cpe:2.3:h:wut:com-server_highspeed_office_1port:-
-
cpe:2.3:h:wut:com-server_highspeed_office_4port:-
-
cpe:2.3:h:wut:com-server_highspeed_poe:-
-
cpe:2.3:h:wut:com-server_highspeed_poe_3x_isolated:-
-
cpe:2.3:h:wut:com-server_highspeed_ul:-
-
cpe:2.3:o:wut:com-server_++_firmware:-
-
cpe:2.3:o:wut:com-server_20ma_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_19"_1port_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_19"_4port_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_compact_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_industry_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_isolated_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_lc_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_oem_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_office_1port_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_office_4port_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_poe_3x_isolated_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_poe_firmware:-
-
cpe:2.3:o:wut:com-server_highspeed_ul_firmware:-