CVE-2023-37857

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. This issue cannot be exploited to bypass the web service authentication of the affected device(s).
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6070-wvps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6101-wxps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6121-wxps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6156-whps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6185-whps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:wp_6215-whps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:12

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-018/ - Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2023-018/ - Third Party Advisory
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 3.8

15 Aug 2023, 17:15

Type Values Removed Values Added
CPE cpe:2.3:o:phoenixcontact:wp_6070-wvps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6185-whps:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:wp_6121-wxps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6101-wxps:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6070-wvps:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6215-whps:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6121-wxps:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:wp_6156-whps:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:wp_6101-wxps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:wp_6185-whps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:wp_6156-whps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:wp_6215-whps_firmware:*:*:*:*:*:*:*:*
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-018/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-018/ - Third Party Advisory
CVSS v2 : unknown
v3 : 3.8
v2 : unknown
v3 : 7.2

09 Aug 2023, 12:46

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-09 07:15

Updated : 2024-11-21 08:12


NVD link : CVE-2023-37857

Mitre link : CVE-2023-37857

CVE.ORG link : CVE-2023-37857


JSON object : View

Products Affected

phoenixcontact

  • wp_6185-whps
  • wp_6215-whps_firmware
  • wp_6101-wxps_firmware
  • wp_6121-wxps
  • wp_6185-whps_firmware
  • wp_6156-whps_firmware
  • wp_6215-whps
  • wp_6070-wvps_firmware
  • wp_6156-whps
  • wp_6070-wvps
  • wp_6121-wxps_firmware
  • wp_6101-wxps
CWE
CWE-798

Use of Hard-coded Credentials