CVE-2022-3738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
19/01/2023
Last modified:
07/11/2023

Description

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:cc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:cc100_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:* 16 (including) 22 (including)


References to Advisories, Solutions, and Tools