PHOENIX CONTACTs WP 6xxx series web panels是德国菲尼克斯电气(PHOENIX CONTACTs)公司的一系列网页面板。 PHOENIX CONTACTs WP 6xxx series web panels 4.0.10 之前版本存在安全漏洞,该漏洞源于在Web 面板中,未经身份验证的远程攻击者可以访问 HTTP API 的上传功能,导致 SSL 连接的证书错误,并可能导致部分拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHOENIX CONTACT | WP 6070-WVPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6101-WXPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6121-WXPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6156-WHPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6185-WHPS | 0 ~ 4.0.10 | - |
|
| PHOENIX CONTACT | WP 6215-WHPS | 0 ~ 4.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-37861 | 8.8 HIGH | PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels |
| CVE-2023-37860 | 7.5 HIGH | PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels |
| CVE-2023-37863 | 7.2 HIGH | PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panels |
| CVE-2023-37859 | 7.2 HIGH | PHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panels |
| CVE-2023-37864 | 7.2 HIGH | PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity check |
| CVE-2023-37858 | 4.9 MEDIUM | PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels |
| CVE-2023-37855 | 4.3 MEDIUM | PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panels |
| CVE-2023-37856 | 4.3 MEDIUM | PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panels |
| CVE-2023-37857 | 3.8 LOW | PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panels |
No comments yet