CVE Feed

    Dashboard / CVE / CVE-2022-4098

    CVE-2022-4098

    Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

    Published:Dec 13, 2022
    Last Modified:Apr 14, 2025
    EPS:Dec 13, 2022
    EPSS Score:0.0003
    CVSS Score:8

    Affected Products

    Vendor
    Wut
    Product
    Com-server 20ma
    Vendor
    Wut
    Product
    Com-server 20ma Firmware
    Vendor
    Wut
    Product
    Com-server \+\+
    Vendor
    Wut
    Product
    Com-server \+\+ Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed 100basefx
    Vendor
    Wut
    Product
    Com-server Highspeed 100basefx Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed 100baselx
    Vendor
    Wut
    Product
    Com-server Highspeed 100baselx Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed 19\" 1port
    Vendor
    Wut
    Product
    Com-server Highspeed 19\" 1port Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed 19\" 4port
    Vendor
    Wut
    Product
    Com-server Highspeed 19\" 4port Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Compact
    Vendor
    Wut
    Product
    Com-server Highspeed Compact Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Industry
    Vendor
    Wut
    Product
    Com-server Highspeed Industry Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Isolated
    Vendor
    Wut
    Product
    Com-server Highspeed Isolated Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Lc
    Vendor
    Wut
    Product
    Com-server Highspeed Lc Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Oem
    Vendor
    Wut
    Product
    Com-server Highspeed Oem Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Office 1port
    Vendor
    Wut
    Product
    Com-server Highspeed Office 1port Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Office 4port
    Vendor
    Wut
    Product
    Com-server Highspeed Office 4port Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Poe
    Vendor
    Wut
    Product
    Com-server Highspeed Poe 3x Isolated
    Vendor
    Wut
    Product
    Com-server Highspeed Poe 3x Isolated Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Poe Firmware
    Vendor
    Wut
    Product
    Com-server Highspeed Ul
    Vendor
    Wut
    Product
    Com-server Highspeed Ul Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High