Show filters
158 Total Results
Displaying 51-60 of 158
Sort by:
Attacker Value
Unknown

CVE-2023-31100

Disclosure Date: November 15, 2023 (last updated February 01, 2024)
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before 4.4.0.217 * from 4.5.0.0 before 4.5.0.138
Attacker Value
Unknown

CVE-2023-3935

Disclosure Date: September 13, 2023 (last updated January 26, 2024)
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Attacker Value
Unknown

CVE-2023-37864

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
Attacker Value
Unknown

CVE-2023-37863

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
Attacker Value
Unknown

CVE-2023-37862

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
Attacker Value
Unknown

CVE-2023-37861

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
Attacker Value
Unknown

CVE-2023-37860

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
Attacker Value
Unknown

CVE-2023-37859

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
Attacker Value
Unknown

CVE-2023-37858

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
Attacker Value
Unknown

CVE-2023-37857

Disclosure Date: August 09, 2023 (last updated November 14, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.