CVE-2022-3738

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2022-054/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:wago:cc100:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:cc100_firmware:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:*

History

07 Nov 2023, 10:15

Type Values Removed Values Added
Summary The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull. The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

Information

Published : 2023-01-19 12:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-3738

Mitre link : CVE-2022-3738

CVE.ORG link : CVE-2022-3738


JSON object : View

Products Affected

wago

  • cc100_firmware
  • touch_panel_600_marine_firmware
  • pfc200_firmware
  • touch_panel_600_advanced_firmware
  • cc100
  • pfc200
  • touch_panel_600_standard
  • edge_controller
  • pfc100_firmware
  • edge_controller_firmware
  • pfc100
  • touch_panel_600_marine
  • touch_panel_600_advanced
  • touch_panel_600_standard_firmware
CWE
CWE-306

Missing Authentication for Critical Function