ZeroHour

CVE-2023-37857

CVSS 3.1
7.2 high
EPSS
<1%p46
Published
()
Modified
Description

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.

Vendors
phoenixcontact
Products
wp 6070-wvps firmware, wp 6101-wxps firmware, wp 6121-wxps firmware, wp 6156-whps firmware, wp 6185-whps firmware, wp 6215-whps firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.