Vulnerability Details CVE-2023-37862
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.9%
CVSS Severity
CVSS v3 Score 8.2
Products affected by CVE-2023-37862
-
cpe:2.3:h:phoenixcontact:wp_6070-wvps:-
-
cpe:2.3:h:phoenixcontact:wp_6101-wxps:-
-
cpe:2.3:h:phoenixcontact:wp_6121-wxps:-
-
cpe:2.3:h:phoenixcontact:wp_6156-whps:-
-
cpe:2.3:h:phoenixcontact:wp_6185-whps:-
-
cpe:2.3:h:phoenixcontact:wp_6215-whps:-
-
cpe:2.3:o:phoenixcontact:wp_6070-wvps_firmware:*
-
cpe:2.3:o:phoenixcontact:wp_6101-wxps_firmware:*
-
cpe:2.3:o:phoenixcontact:wp_6121-wxps_firmware:*
-
cpe:2.3:o:phoenixcontact:wp_6156-whps_firmware:*
-
cpe:2.3:o:phoenixcontact:wp_6185-whps_firmware:*
-
cpe:2.3:o:phoenixcontact:wp_6215-whps_firmware:*