The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wago
Subscribe
|
Cc100
Subscribe
Cc100 Firmware
Subscribe
Edge Controller
Subscribe
Edge Controller Firmware
Subscribe
Pfc100
Subscribe
Pfc100 Firmware
Subscribe
Pfc200
Subscribe
Pfc200 Firmware
Subscribe
Touch Panel 600 Advanced
Subscribe
Touch Panel 600 Advanced Firmware
Subscribe
Touch Panel 600 Marine
Subscribe
Touch Panel 600 Marine Firmware
Subscribe
Touch Panel 600 Standard
Subscribe
Touch Panel 600 Standard Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43094 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-054/ |
|
History
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-02T14:55:51.603Z
Reserved: 2022-10-28T07:18:40.653Z
Link: CVE-2022-3738
Updated: 2024-08-03T01:20:57.784Z
Status : Modified
Published: 2023-01-19T12:15:11.213
Modified: 2024-11-21T07:20:08.493
Link: CVE-2022-3738
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD