CVE Database
/

CVE-2022-3738

Back to search

CVE-2022-3738

Published: Jan 19, 2023

Modified: Apr 2, 2025

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

VendorProductVersions

WAGO

Series WAGO PFC100

affected
FW16 - <= FW22

WAGO

Series WAGO PFC200

affected
FW16 - <= FW22

WAGO

Series WAGO Touch Panel 600 Advanced Line

affected
FW16 - <= FW22

WAGO

Series WAGO Touch Panel 600 Marine Line

affected
FW16 - <= FW22

WAGO

Series WAGO Touch Panel 600 Standard Line

affected
FW16 - <= FW22

WAGO

WAGO Compact Controller CC100

affected
FW16 - <= FW22

WAGO

WAGO Edge Controller

affected
FW16 - <= FW22

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now