PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
CVE-2023-37862
8.2HIGH
What is CVE-2023-37862?
In the WP 6xxx series web panels from PHOENIX CONTACT prior to version 4.0.10, an unauthenticated remote attacker can exploit vulnerabilities in the HTTP API's upload functions. This access can lead to SSL certificate errors, potentially resulting in a partial denial-of-service. Users of affected versions should take immediate action to mitigate the risks associated with this vulnerability.
Affected Version(s)
WP 6070-WVPS 0 < 4.0.10
WP 6101-WXPS 0 < 4.0.10
WP 6121-WXPS 0 < 4.0.10