7.2

CVE-2023-37859

PHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panels

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Wp 6070-wvps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6070-wvps Version -
Phoenixcontact ≫ Wp 6101-wxps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6101-wxps Version -
Phoenixcontact ≫ Wp 6121-wxps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6121-wxps Version -
Phoenixcontact ≫ Wp 6156-whps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6156-whps Version -
Phoenixcontact ≫ Wp 6185-whps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6185-whps Version -
Phoenixcontact ≫ Wp 6215-whps Firmware Version < 4.0.10
   Phoenixcontact ≫ Wp 6215-whps Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.552
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
info@cert.vde.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://cert.vde.com/en/advisories/VDE-2023-018/
Third Party Advisory