PHOENIX CONTACTs WP 6xxx series web panels是德国菲尼克斯电气(PHOENIX CONTACTs)公司的一系列网页面板。 PHOENIX CONTACTs WP 6xxx series web panels 4.0.10之前版本存在操作系统命令注入漏洞,该漏洞源于低权限的远程攻击者可能会使用特定的HTTP DELETE请求来获得对设备的完全访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHOENIX CONTACT | WP 6070-WVPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6101-WXPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6121-WXPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6156-WHPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6185-WHPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6215-WHPS | 0 ~ 4.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3572 | 10.0 CRITICAL | PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels |
| CVE-2023-3526 | 9.6 CRITICAL | PHOENIX CONTACT: Cross-site Scripting vulnerability in TC ROUTER, TC CLOUD CLIENT and CLOU |
| CVE-2023-3573 | 8.8 HIGH | PHOENIX CONTACT: Command Injection in WP 6xxx Web panels |
| CVE-2023-3571 | 8.8 HIGH | PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels |
| CVE-2023-3569 | 4.9 MEDIUM | PHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIEN |
No comments yet