CVE-2022-45138

CRITICAL

WAGO PFC100/PFC200/751-9301/752-8303/8000-002 & Touch Panel 600 Firmware 16-21 - Unauthenticated Configuration Access

Title source: llm
STIX 2.1

Description

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0074
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (21)
wago/751-9301_firmware 22
wago/751-9301_firmware 23
wago/751-9301_firmware 16 - 22
wago/752-8303\/8000-002_firmware 22
wago/752-8303\/8000-002_firmware 23
wago/752-8303\/8000-002_firmware 18 - 22
wago/pfc100_firmware 22
wago/pfc100_firmware 23
wago/pfc100_firmware 16 - 22
wago/pfc200_firmware 22
... and 11 more
Published Feb 27, 2023
Tracked Since Feb 18, 2026