Vulnerabilities > Phoenixcontact > WP 6070 Wvps Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-08-09 CVE-2023-37855 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
network
low complexity
phoenixcontact CWE-610
4.3
2023-08-09 CVE-2023-37856 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
network
low complexity
phoenixcontact CWE-610
4.3
2023-08-09 CVE-2023-37858 Missing Encryption of Sensitive Data vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
network
low complexity
phoenixcontact CWE-311
4.9