CVE-2022-22511
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
09/03/2022
Last modified:
18/03/2022
Description
Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wago:750-8100_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:750-8100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8101_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:750-8101:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8102_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:750-8102:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:751-9301_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:751-9301:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:750-8202:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:762-4205\/8000-002_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:762-4205\/8000-002:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:762-4206\/8000-002_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
| cpe:2.3:h:wago:762-4206\/8000-002:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wago:762-4305\/8000-002_firmware:*:*:*:*:*:*:*:* | fw16 (including) | fw22 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



