7.2
CVE-2023-37864
- EPSS 0.24%
- Veröffentlicht 09.08.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:12:21
- Quelle info@cert.vde.com
- Teams Watchlist Login
- Unerledigt Login
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Wp 6070-wvps Firmware Version < 4.0.10
Phoenixcontact ≫ Wp 6101-wxps Firmware Version < 4.0.10
Phoenixcontact ≫ Wp 6121-wxps Firmware Version < 4.0.10
Phoenixcontact ≫ Wp 6156-whps Firmware Version < 4.0.10
Phoenixcontact ≫ Wp 6185-whps Firmware Version < 4.0.10
Phoenixcontact ≫ Wp 6215-whps Firmware Version < 4.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.468 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
info@cert.vde.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-494 Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.