CVE-2022-45139
MEDIUMWAGO PFC100, PFC200, 751-9301, 752-8303/8000-002, Touch Panel 600 Firmware 16-21 - CORS Misconfiguration
Title source: llmDescription
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
References (1)
Core 1
Core References
Third Party Advisory
https://cert.vde.com/en/advisories/VDE-2022-060/
Scores
CVSS v3
5.3
EPSS
0.0025
EPSS Percentile
16.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-346
Status
published
Products (21)
wago/751-9301_firmware
22
wago/751-9301_firmware
23
wago/751-9301_firmware
16 - 22
wago/752-8303\/8000-002_firmware
22
wago/752-8303\/8000-002_firmware
23
wago/752-8303\/8000-002_firmware
18 - 22
wago/pfc100_firmware
22
wago/pfc100_firmware
23
wago/pfc100_firmware
16 - 22
wago/pfc200_firmware
22
... and 11 more
Published
Feb 27, 2023
Tracked Since
Feb 18, 2026