CVE Vulnerabilities

CVE-2022-45139

Origin Validation Error

Published: Feb 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
751-9301_firmwareWago16 (including)22 (excluding)
751-9301_firmwareWago22 (including)22 (including)
751-9301_firmwareWago23 (including)23 (including)

References