AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-4098

HIGH · CVSS 8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-12-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-4098
Severity
HIGH
CVSS
8
EPSS
0.34%

Original NVD Description

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.