MEDIUM · 5.9

CVE-2022-3738

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A...

Vulnerability Description

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WagoPfc100 Firmware>= 16, <= 22
WagoPfc100-
WagoPfc200 Firmware>= 16, <= 22
WagoPfc200-
WagoTouch Panel 600 Advanced Firmware>= 16, <= 22
WagoTouch Panel 600 Advanced-
WagoTouch Panel 600 Standard Firmware>= 16, <= 22
WagoTouch Panel 600 Standard-
WagoTouch Panel 600 Marine Firmware>= 16, <= 22
WagoTouch Panel 600 Marine-
WagoCc100 Firmware>= 16, <= 22
WagoCc100-
WagoEdge Controller Firmware>= 16, <= 22
WagoEdge Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-3738?

CVE-2022-3738 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A...

How severe is CVE-2022-3738?

CVE-2022-3738 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-3738?

Check the references section above for vendor advisories and patch information. Affected products include: Wago Pfc100 Firmware, Wago Pfc100, Wago Pfc200 Firmware, Wago Pfc200, Wago Touch Panel 600 Advanced Firmware.