Phoenixcontact
Phoenixcontact WP 6215-whps Firmware: vulnerabilidades y CVE
Phoenixcontact WP 6215-whps Firmware tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-37864 | Alta (7.2) | 0.42% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. |
| CVE-2023-37863 | Alta (7.2) | 0.93% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. |
| CVE-2023-37862 | Alta (8.2) | 0.50% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might… |
| CVE-2023-37861 | Alta (8.8) | 0.88% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the… |
| CVE-2023-37860 | Alta (7.5) | 0.80% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon. |
| CVE-2023-37859 | Alta (7.2) | 0.86% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system… |
| CVE-2023-37858 | Media (4.9) | 0.45% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web… |
| CVE-2023-37857 | Alta (7.2) | 0.58% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid… |
| CVE-2023-37856 | Media (4.3) | 0.57% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the… |
| CVE-2023-37855 | Media (4.3) | 0.57% | — | 9 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser. |
| CVE-2023-3573 | Alta (8.8) | 1.2% | — | 8 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full… |
| CVE-2023-3572 | Crítica (9.9) | 1.0% | — | 8 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to… |
| CVE-2023-3571 | Alta (8.8) | 0.59% | — | 8 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device. |
| CVE-2023-3570 | Alta (8.8) | 0.93% | — | 8 ago 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device. |
Otros productos de Phoenixcontact
Charx Sec-3100 Firmware · 29Charx Sec-3050 Firmware · 29Charx Sec-3000 Firmware · 29Charx Sec-3150 Firmware · 29FL Mguard Rs4004 Tx/dtx Firmware · 16FL Mguard Rs4004 Tx/dtx VPN Firmware · 16FL Mguard Core TX VPN Firmware · 15FL Mguard Gt/gt VPN Firmware · 15FL Mguard Delta Tx/tx Firmware · 15FL Mguard Delta Tx/tx VPN Firmware · 15FL Mguard Centerport Vpn-1000 Firmware · 15FL Mguard Core TX Firmware · 15