CVE-2022-4098

CVE-2022-4098

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. During an authenticated session to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

Source: CVE-2022-4098

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다