CRITICAL · 9.8

CVE-2022-45140

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromi...

Vulnerability Description

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Wago751-9301 Firmware>= 16, < 22
Wago751-9301-
Wago752-8303\/8000-002 Firmware>= 18, < 22
Wago752-8303\/8000-002-
WagoPfc100 Firmware>= 16, < 22
WagoPfc100-
WagoPfc200 Firmware>= 16, < 22
WagoPfc200-
WagoTouch Panel 600 Advanced Firmware>= 16, < 22
WagoTouch Panel 600 Advanced-
WagoTouch Panel 600 Marine Firmware>= 16, < 22
WagoTouch Panel 600 Marine-
WagoTouch Panel 600 Standard Firmware>= 16, < 22
WagoTouch Panel 600 Standard-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-45140?

CVE-2022-45140 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromi...

How severe is CVE-2022-45140?

CVE-2022-45140 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-45140?

Check the references section above for vendor advisories and patch information. Affected products include: Wago 751-9301 Firmware, Wago 751-9301, Wago 752-8303\/8000-002 Firmware, Wago 752-8303\/8000-002, Wago Pfc100 Firmware.