CVE Vulnerabilities

CVE-2023-37855

Externally Controlled Reference to a Resource in Another Sphere

Published: Aug 09, 2023 | Modified: Aug 15, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Wp_6070-wvps_firmware Phoenixcontact * 4.0.10 (excluding)

References