HIGH · 8.0

CVE-2022-4098

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in ...

Vulnerability Description

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WutCom-Server \+\+ Firmware< 1.55
WutCom-Server \+\+-
WutCom-Server 20Ma Firmware< 1.55
WutCom-Server 20Ma-
WutCom-Server Highspeed 100Basefx Firmware< 1.78
WutCom-Server Highspeed 100Basefx-
WutCom-Server Highspeed 100Baselx Firmware< 1.78
WutCom-Server Highspeed 100Baselx-
WutCom-Server Highspeed 19\" 1Port Firmware< 1.78
WutCom-Server Highspeed 19\" 1Port-
WutCom-Server Highspeed 19\" 4Port Firmware< 1.78
WutCom-Server Highspeed 19\" 4Port-
WutCom-Server Highspeed Compact Firmware< 1.78
WutCom-Server Highspeed Compact-
WutCom-Server Highspeed Industry Firmware< 1.78
WutCom-Server Highspeed Industry-
WutCom-Server Highspeed Isolated Firmware< 1.78
WutCom-Server Highspeed Isolated-
WutCom-Server Highspeed Oem Firmware< 1.78
WutCom-Server Highspeed Oem-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-4098?

CVE-2022-4098 is a vulnerability with a CVSS score of 8.0 (HIGH). Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in ...

How severe is CVE-2022-4098?

CVE-2022-4098 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-4098?

Check the references section above for vendor advisories and patch information. Affected products include: Wut Com-Server \+\+ Firmware, Wut Com-Server \+\+, Wut Com-Server 20Ma Firmware, Wut Com-Server 20Ma, Wut Com-Server Highspeed 100Basefx Firmware.