Show filters
744 Total Results
Displaying 171-180 of 744
Sort by:
Attacker Value
Unknown
CVE-2023-37862
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
0
Attacker Value
Unknown
CVE-2023-37861
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
0
Attacker Value
Unknown
CVE-2023-37860
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
0
Attacker Value
Unknown
CVE-2023-37859
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
0
Attacker Value
Unknown
CVE-2023-37858
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
0
Attacker Value
Unknown
CVE-2023-37857
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.
0
Attacker Value
Unknown
CVE-2023-37856
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
0
Attacker Value
Unknown
CVE-2023-37855
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
0
Attacker Value
Unknown
CVE-2023-2905
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.
0
Attacker Value
Unknown
CVE-2023-38384
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions.
0