Back

HIGH

Wiesemann & Theis: Multiple products prone to missing authentication through spoofing

Published Dec 13, 2022

Description

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CERTVDE
Published Dec 13, 2022
Updated Apr 14, 2025
Reserved Nov 21, 2022

CISA Vulnrichment

Updated Apr 14, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner CERTVDE
Published Dec 13, 2022
Updated Apr 14, 2025

GitHub

No data