ZeroHour

CVE-2022-3738

CVSS 3.1
5.9 medium
EPSS
<1%p48
Published
()
Modified
Description

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

Vendors
wago
Products
pfc100 firmware, pfc200 firmware, touch panel 600 advanced firmware, touch panel 600 standard firmware, touch panel 600 marine firmware, cc100 firmware, edge controller firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.