CVE-2022-4098
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2022
Last modified:
31/03/2023
Description
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wut:com-server_\+\+_firmware:*:*:*:*:*:*:*:* | 1.55 (excluding) | |
| cpe:2.3:h:wut:com-server_\+\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_20ma_firmware:*:*:*:*:*:*:*:* | 1.55 (excluding) | |
| cpe:2.3:h:wut:com-server_20ma:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_100basefx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_100baselx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_19\"_1port_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_19\"_1port:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_19\"_4port_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_19\"_4port:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_compact_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_compact:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_industry_firmware:*:*:*:*:*:*:*:* | 1.78 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



