Vulnerability Details CVE-2022-45139
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.3%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-45139
-
cpe:2.3:h:wago:751-9301:-
-
cpe:2.3:h:wago:752-8303/8000-002:-
-
-
-
cpe:2.3:h:wago:touch_panel_600_advanced:-
-
cpe:2.3:h:wago:touch_panel_600_marine:-
-
cpe:2.3:h:wago:touch_panel_600_standard:-
-
cpe:2.3:o:wago:751-9301_firmware:*
-
cpe:2.3:o:wago:751-9301_firmware:22
-
cpe:2.3:o:wago:751-9301_firmware:23
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:18
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:22
-
cpe:2.3:o:wago:752-8303/8000-002_firmware:23
-
cpe:2.3:o:wago:pfc100_firmware:16
-
cpe:2.3:o:wago:pfc100_firmware:20
-
cpe:2.3:o:wago:pfc100_firmware:22
-
cpe:2.3:o:wago:pfc100_firmware:23
-
cpe:2.3:o:wago:pfc200_firmware:16
-
cpe:2.3:o:wago:pfc200_firmware:20
-
cpe:2.3:o:wago:pfc200_firmware:22
-
cpe:2.3:o:wago:pfc200_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_marine_firmware:23
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:16
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:22
-
cpe:2.3:o:wago:touch_panel_600_standard_firmware:23