Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3573


In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.


Published

2023-08-08T07:15:10.957

Last Modified

2024-11-21T08:17:34.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact wp_6070-wvps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6070-wvps - No
Operating System phoenixcontact wp_6101-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6101-wxps - No
Operating System phoenixcontact wp_6121-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6121-wxps - No
Operating System phoenixcontact wp_6156-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6156-whps - No
Operating System phoenixcontact wp_6185-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6185-whps - No
Operating System phoenixcontact wp_6215-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6215-whps - No

References