CVE-2023-37857: PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.
Other sources
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. This issue cannot be exploited to bypass the web service authentication of the affected device(s).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37857?
CVE-2023-37857 is a vulnerability in PHOENIX CONTACT's WP 6xxx series web panels that allows an authenticated remote attacker with admin privileges to read hardcoded cryptographic keys and create valid session cookies.
How severe is CVE-2023-37857?
CVE-2023-37857 has a severity rating of 7.2 (high).
Which versions of PHOENIX CONTACT's WP 6xxx series web panels are affected by CVE-2023-37857?
Versions prior to 4.0.10 of PHOENIX CONTACT's WP 6xxx series web panels are affected by CVE-2023-37857.
How can an attacker exploit CVE-2023-37857?
An attacker with admin privileges can exploit CVE-2023-37857 to read hardcoded cryptographic keys and create valid session cookies, potentially bypassing web service authentication.
Is there a fix for CVE-2023-37857?
Updating PHOENIX CONTACT's WP 6xxx series web panels to version 4.0.10 or later will fix CVE-2023-37857.