Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-37857
HistoryAug 09, 2023 - 7:15 a.m.

Hardcoded credentials

2023-08-0907:15:00
PRIOn knowledge base
www.prio-n.com
8
phoenix contacts
web panels
remote attacker
admin privileges
cryptographic keys
cookies
valid session

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.1%

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.1%

Related for PRION:CVE-2023-37857