CVE-2023-37862: PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37862.
What is the severity level of CVE-2023-37862?
The severity level of CVE-2023-37862 is high with a score of 8.2.
Which software versions are affected by CVE-2023-37862?
The PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 are affected by CVE-2023-37862.
What is the impact of CVE-2023-37862?
CVE-2023-37862 allows an unauthenticated remote attacker to access upload-functions of the HTTP API, which can cause certificate errors for SSL-connections and result in a partial denial-of-service.
Where can I find more information about CVE-2023-37862?
You can find more information about CVE-2023-37862 at the following link: [VDE-2023-018](https://cert.vde.com/en/advisories/VDE-2023-018/)