CVE-2022-42787
Estado: ModificadaAlta (8.8)—
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.78%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (17)
WUT — At-modem-emulator FirmwareWUT — Com-server ++ FirmwareWUT — Com-server 20ma FirmwareWUT — Com-server Highspeed 100basefx FirmwareWUT — Com-server Highspeed 100baselx FirmwareWUT — Com-server Highspeed 19" 1port FirmwareWUT — Com-server Highspeed 19" 4port FirmwareWUT — Com-server Highspeed Compact FirmwareWUT — Com-server Highspeed Industry FirmwareWUT — Com-server Highspeed Isolated FirmwareWUT — Com-server Highspeed LC FirmwareWUT — Com-server Highspeed OEM FirmwareWUT — Com-server Highspeed Office 1port FirmwareWUT — Com-server Highspeed Office 4port FirmwareWUT — Com-server Highspeed POE 3X Isolated FirmwareWUT — Com-server Highspeed POE FirmwareWUT — Com-server Highspeed UL Firmware
CWE
- CWE-330
- CWE-330
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-42787",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-42787",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-01T19:01:02.435905Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server LC",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server PoE 3 x Isolated",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server 20mA",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server ++",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "AT-Modem-Emulator",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server UL",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.48",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed 100BaseFX",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed 100BaseLX",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed Office 1 Port",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed Office 4 Port",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed Industry",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed OEM",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed Compact",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed Isolated",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed 19\" 1Port",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed 19\" 4Port",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Wiesemann & Theis",
"product": "Com-Server Highspeed PoE",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "1.76",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-11-10T12:15:10.927",
"references": [
{
"url": "https://cert.vde.com/de/advisories/VDE-2022-043",
"tags": [
"Vendor Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/de/advisories/VDE-2022-043",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-330"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-330"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required."
},
{
"lang": "es",
"value": "Productos multiples W&T de Comserver Series utilizan un pequeño espacio numérico para asignar identificadores de sesión. Después de iniciar sesión de un usuario, un atacante remoto no autenticado puede forzar la identificación de sesión del usuario y obtener acceso a su cuenta en el dispositivo. Como el usuario necesita iniciar sesión para que el ataque tenga éxito, se requiere la interacción del usuario."
}
],
"lastModified": "2026-06-17T05:05:19.743",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:at-modem-emulator_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D1C1F81-27B4-40D1-A5BD-28A20E85426A",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:at-modem-emulator:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9C4BCB98-14B9-4B24-AC86-88778BE94A1A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_\\+\\+_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D694696-F36F-48EF-9902-3EC4B17436C3",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_\\+\\+:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "95A959DC-16BA-4F52-BC0E-8C005C00B20B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_20ma_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73EFD090-75E1-4626-83BC-F90C66C492C1",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_20ma:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED79295D-3E94-4396-ADB0-A346B0A2AF63"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A68F28E-5EEF-4318-B146-97F87CA8DEF0",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_100basefx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E7624DA1-E509-4BAA-A44C-BC4E16D9FCB1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65D19EE8-3570-4C87-B8E6-9450FD575587",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_100baselx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B36DF0EE-58C2-4CC4-99C8-55FCDDC9597B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_19\\\"_1port_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04FF98FC-5480-4F36-8257-0622229B55BF",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_19\\\"_1port:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "65311BF2-70D2-475B-A314-0465FAA24E7F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_19\\\"_4port_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F211D204-8DF4-436F-97ED-E96439FA1405",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_19\\\"_4port:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B0099261-FBC5-4C6D-8558-E7F4BAD401AB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_compact_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5A39967-43C7-490A-9A4E-8D2304D6F6BB",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_compact:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0F0E0076-658C-49E2-ACEF-A4109A22DEDA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_industry_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F45FCF96-6419-4BD4-9646-6853E1753571",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_industry:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E1ACF76-3B54-4960-9A44-19F5CED2216C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_isolated_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB67B2D9-F924-47F1-937B-C6AC5BE63BBC",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_isolated:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "53646CB3-FAC9-447B-8762-66E20790041F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_oem_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48836121-BB41-4E0E-A8F6-085EA12C3EC2",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_oem:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A47245FC-FDD7-40E6-B78F-28E5902E052D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_office_1port_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31849A47-81EE-40F2-986B-67041583E9F4",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_office_1port:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "62A566FD-B617-45DC-B0E8-D130C0BCF13E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_office_4port_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DBF947FE-F111-4A2D-A78C-F6CE6139860F",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_office_4port:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "255D4A95-1A11-45F7-B14F-BC74F6D190AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_poe_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2CA2668-1B7D-48F3-9310-0CE6FA036645",
"versionEndExcluding": "1.76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_poe:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0E25680B-D264-4562-B3AB-D6BAF0BEA433"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_lc_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DFE2270-9EFA-4185-860A-BDB6A8024B5D",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_lc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B0567E35-5011-4C17-8737-A20F55922F59"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_ul_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68BD57D3-8F57-4A94-BD6C-FFD157DE0FFD",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_ul:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5C5BB32C-F7B5-4E34-A60A-DDA084EB3F45"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wut:com-server_highspeed_poe_3x_isolated_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3ABB392-20C8-401E-9968-7A1FB578F07B",
"versionEndExcluding": "1.48"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wut:com-server_highspeed_poe_3x_isolated:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F851852B-75EA-4F1C-8BFB-DE29394D510B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}