CVE Vulnerabilities

CVE-2022-45139

Origin Validation Error

Published: Feb 27, 2023 | Modified: Mar 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
751-9301_firmware Wago 16 (including) 22 (excluding)
751-9301_firmware Wago 22 (including) 22 (including)
751-9301_firmware Wago 23 (including) 23 (including)

References