Vulnerability Details CVE-2022-45137
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.9%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2022-45137
-
cpe:2.3:h:wago:751-9301:-
-
cpe:2.3:h:wago:752-8303/8000-002:-
-
-
-
cpe:2.3:h:wago:touch_panel_600_advanced:-
-
cpe:2.3:h:wago:touch_panel_600_marine:-
-
cpe:2.3:h:wago:touch_panel_600_standard:-
-
cpe:2.3:o:wago:751-9301_firmware:*
-
cpe:2.3:o:wago:751-9301_firmware:22
-
cpe:2.3:o:wago:751-9301_firmware:23
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:18
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:22
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:23
-
cpe:2.3:o:wago:pfc100_firmware:16
-
cpe:2.3:o:wago:pfc100_firmware:20
-
cpe:2.3:o:wago:pfc100_firmware:22
-
cpe:2.3:o:wago:pfc100_firmware:23
-
cpe:2.3:o:wago:pfc200_firmware:16
-
cpe:2.3:o:wago:pfc200_firmware:20
-
cpe:2.3:o:wago:pfc200_firmware:22
-
cpe:2.3:o:wago:pfc200_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:23