VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels

CVE-2023-37862

Description

Unauthenticated remote attacker can access upload functions of HTTP API in WP 6xxx web panels prior to 4.0.10, triggering certificate errors and partial denial-of-service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated remote attacker can access upload functions of HTTP API in WP 6xxx web panels prior to 4.0.10, triggering certificate errors and partial denial-of-service.

Vulnerability

In PHOENIX CONTACT's WP 6xxx series web panels, versions prior to 4.0.10, an unauthenticated remote attacker can access upload functions of the HTTP API. This vulnerability exists due to missing authentication on those endpoints. The affected products include various WP 6xxx models [1].

Exploitation

The attacker does not require any authentication or prior access. By sending crafted HTTP requests to the upload functions, the attacker can trigger certificate errors for SSL connections. The exact steps involve accessing the upload API endpoints without credentials [1].

Impact

Successful exploitation may cause certificate errors for SSL connections, leading to a partial denial-of-service. The confidentiality and integrity of communications may be compromised due to degraded TLS security. The attacker does not gain code execution or data access directly from this vulnerability [1].

Mitigation

The vulnerability is fixed in version 4.0.10 of the WP 6xxx firmware. Users should update to this version or later. There are no reported workarounds; however, restricting network access to the web panel can reduce exposure [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.