Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37864


In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.


Published

2023-08-09T07:15:11.323

Last Modified

2024-11-21T08:12:21.450

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-494
  • Type: Primary
    CWE-494

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact wp_6070-wvps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6070-wvps - No
Operating System phoenixcontact wp_6101-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6101-wxps - No
Operating System phoenixcontact wp_6121-wxps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6121-wxps - No
Operating System phoenixcontact wp_6156-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6156-whps - No
Operating System phoenixcontact wp_6185-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6185-whps - No
Operating System phoenixcontact wp_6215-whps_firmware < 4.0.10 Yes
Hardware phoenixcontact wp_6215-whps - No

References