CVE-2022-22511

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/03/2022
Last modified:
18/03/2022

Description

Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wago:750-8100_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:750-8100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-8101_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:750-8101:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-8102_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:750-8102:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:751-9301_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:751-9301:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:750-8202:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:762-4205\/8000-002_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:762-4205\/8000-002:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:762-4206\/8000-002_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)
cpe:2.3:h:wago:762-4206\/8000-002:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:762-4305\/8000-002_firmware:*:*:*:*:*:*:*:* fw16 (including) fw22 (excluding)


References to Advisories, Solutions, and Tools