7.2

CVE-2023-37857

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies.  These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.

Data is provided by the National Vulnerability Database (NVD)
PhoenixcontactWp 6070-wvps Firmware Version < 4.0.10
   PhoenixcontactWp 6070-wvps Version-
PhoenixcontactWp 6101-wxps Firmware Version < 4.0.10
   PhoenixcontactWp 6101-wxps Version-
PhoenixcontactWp 6121-wxps Firmware Version < 4.0.10
   PhoenixcontactWp 6121-wxps Version-
PhoenixcontactWp 6156-whps Firmware Version < 4.0.10
   PhoenixcontactWp 6156-whps Version-
PhoenixcontactWp 6185-whps Firmware Version < 4.0.10
   PhoenixcontactWp 6185-whps Version-
PhoenixcontactWp 6215-whps Firmware Version < 4.0.10
   PhoenixcontactWp 6215-whps Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.195
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
info@cert.vde.com 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.