Show filters
639 Total Results
Displaying 71-80 of 639
Sort by:
Attacker Value
Unknown
CVE-2023-37859
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
0
Attacker Value
Unknown
CVE-2023-37858
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
0
Attacker Value
Unknown
CVE-2023-37857
Disclosure Date: August 09, 2023 (last updated November 14, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.
0
Attacker Value
Unknown
CVE-2023-37856
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
0
Attacker Value
Unknown
CVE-2023-37855
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
0
Attacker Value
Unknown
CVE-2023-28575
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
0
Attacker Value
Unknown
CVE-2023-28537
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption while allocating memory in COmxApeDec module in Audio.
0
Attacker Value
Unknown
CVE-2023-22666
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in Audio while playing amrwbplus clips with modified content.
0
Attacker Value
Unknown
CVE-2023-21626
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
0
Attacker Value
Unknown
CVE-2022-40510
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
0