Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37857


In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.


Published

2023-08-09T07:15:10.603

Last Modified

2024-11-21T08:12:19.860

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.8 (LOW)

Weaknesses
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact wp_6070-wvps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6070-wvps - No
Operating System phoenixcontact wp_6101-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6101-wxps - No
Operating System phoenixcontact wp_6121-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6121-wxps - No
Operating System phoenixcontact wp_6156-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6156-whps - No
Operating System phoenixcontact wp_6185-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6185-whps - No
Operating System phoenixcontact wp_6215-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6215-whps - No

References