« Volver al listado

CVE-2022-3738

Estado: ModificadaMedia (5.9)—

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-3738",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-3738",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T14:55:30.723734Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "WAGO",
          "product": "Series WAGO PFC100",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "Series WAGO PFC200",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "Series WAGO Touch Panel 600 Advanced Line",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "Series WAGO Touch Panel 600 Marine Line",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "Series WAGO Touch Panel 600 Standard Line",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "WAGO Compact Controller CC100",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WAGO",
          "product": "WAGO Edge Controller",
          "versions": [
            {
              "status": "affected",
              "version": "FW16",
              "versionType": "semver",
              "lessThanOrEqual": "FW22"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-19T12:15:11.213",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-054/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-054/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.\n"
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad permite a un atacante remoto no autenticado descargar un archivo de copia de seguridad, si existe. Ese archivo de copia de seguridad puede contener información confidencial, como credenciales y material criptográfico. Un usuario válido debe crear una copia de seguridad después del último reinicio para que este ataque tenga éxito."
    }
  ],
  "lastModified": "2026-06-17T05:00:12.340",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15CC83F6-9816-482C-A026-7654BCC95D40",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:pfc100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8F636354-95A2-4B36-9666-1FA57F185432"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A4AEA6B-206A-4CEA-ACCE-145B139DF58B",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:pfc200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "688A3248-7EAA-499D-A47C-A4D4900CDBD1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:touch_panel_600_advanced_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35EF27EB-EE11-47B6-8382-47910AA3966B",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:touch_panel_600_advanced:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A8221861-7455-41D5-B310-6AEA822B46CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:touch_panel_600_standard_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A470D085-96C4-4DFE-A4E2-1407D49A4D9A",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:touch_panel_600_standard:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E6D7A44C-2D95-4F69-A7DB-435B0A6F9F03"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:touch_panel_600_marine_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79C7DB93-4282-49DB-B81E-44BBD826BFF8",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:touch_panel_600_marine:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "83DEFFBC-934D-43BE-92AE-25F8EE8C1E0A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:cc100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A3E10E2-A0AA-47E2-B314-51A86BEB2208",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:cc100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "632388B3-E59E-480E-9F0F-08A9F4E87159"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wago:edge_controller_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F31F6E66-78B4-4F7B-BAE6-0C38D1307A4B",
              "versionEndIncluding": "22",
              "versionStartIncluding": "16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wago:edge_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2DFC57C8-6AF4-4771-B0A0-744137FBFECF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}