Description
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44224 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2023-018/ |
|
History
Tue, 15 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Phoenixcontact
Subscribe
Wp 6070-wvps
Subscribe
Wp 6070-wvps Firmware
Subscribe
Wp 6101-wxps
Subscribe
Wp 6101-wxps Firmware
Subscribe
Wp 6121-wxps
Subscribe
Wp 6121-wxps Firmware
Subscribe
Wp 6156-whps
Subscribe
Wp 6156-whps Firmware
Subscribe
Wp 6185-whps
Subscribe
Wp 6185-whps Firmware
Subscribe
Wp 6215-whps
Subscribe
Wp 6215-whps Firmware
Subscribe
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-10-15T19:23:30.106Z
Reserved: 2023-07-10T07:53:14.441Z
Link: CVE-2023-3573
Updated: 2024-08-02T07:01:57.067Z
Status : Modified
Published: 2023-08-08T07:15:10.957
Modified: 2024-11-21T08:17:34.737
Link: CVE-2023-3573
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD