CVE-2023-37858: PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability of CVE-2023-37858?
The vulnerability allows an authenticated remote attacker with admin privileges to read hardcoded cryptographic keys and decrypt an encrypted web application login password.
Which software versions are affected by CVE-2023-37858?
PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 are affected.
What is the severity of CVE-2023-37858?
The severity of the vulnerability is medium with a CVSS score of 4.9.
How can an attacker exploit CVE-2023-37858?
An authenticated remote attacker with admin privileges can exploit the vulnerability to read hardcoded cryptographic keys and decrypt an encrypted web application login password.
Where can I find more information about CVE-2023-37858?
More information about the vulnerability can be found at the following reference: https://cert.vde.com/en/advisories/VDE-2023-018/