CVE-2023-37856: PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panels
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-37856.
What is the severity of CVE-2023-37856?
The severity of CVE-2023-37856 is medium with a severity value of 4.3.
Which software versions are affected by CVE-2023-37856?
PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 are affected by CVE-2023-37856.
How can a remote attacker exploit CVE-2023-37856?
A remote attacker with low privileges can gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser in PHOENIX CONTACTs WP 6xxx series web panels.
Is there a fix available for CVE-2023-37856?
Yes, updating to version 4.0.10 or newer of the PHOENIX CONTACTs WP 6xxx series web panels firmware will fix the vulnerability.