CVE-2022-4098

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2022
Last modified:
31/03/2023

Description

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wut:com-server_\+\+_firmware:*:*:*:*:*:*:*:* 1.55 (excluding)
cpe:2.3:h:wut:com-server_\+\+:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_20ma_firmware:*:*:*:*:*:*:*:* 1.55 (excluding)
cpe:2.3:h:wut:com-server_20ma:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)
cpe:2.3:h:wut:com-server_highspeed_100basefx:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)
cpe:2.3:h:wut:com-server_highspeed_100baselx:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_19\"_1port_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)
cpe:2.3:h:wut:com-server_highspeed_19\"_1port:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_19\"_4port_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)
cpe:2.3:h:wut:com-server_highspeed_19\"_4port:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_compact_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)
cpe:2.3:h:wut:com-server_highspeed_compact:-:*:*:*:*:*:*:*
cpe:2.3:o:wut:com-server_highspeed_industry_firmware:*:*:*:*:*:*:*:* 1.78 (excluding)


References to Advisories, Solutions, and Tools