CVE-2023-24015

A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be ...

Continue Reading
CVE-2023-23903

An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return a ...

Continue Reading
CVE-2023-37858

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an en ...

Continue Reading

CVSS3 - LOW

CVSS2 - MEDIUM

CVE-2023-37862

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-co ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-37861

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a ce ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-37863

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.Read Mor ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-37864

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.Read Mor ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-26310

There is a command injection problem in the old version of the mobile phone backup app.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: