Phoenixcontact Wp 6185-Whps Firmware vulnerabilities
14 known vulnerabilities affecting phoenixcontact/wp_6185-whps_firmware.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-37860HIGHCVSS 7.5fixed in 4.0.102023-08-09
CVE-2023-37860 [HIGH] CWE-862 CVE-2023-37860: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated a
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
nvd
CVE-2023-37863HIGHCVSS 7.2fixed in 4.0.102023-08-09
CVE-2023-37863 [HIGH] CWE-78 CVE-2023-37863: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNM
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
nvd
CVE-2023-37859HIGHCVSS 7.2fixed in 4.0.102023-08-09
CVE-2023-37859 [HIGH] CWE-269 CVE-2023-37859: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
nvd
CVE-2023-37862HIGHCVSS 8.2fixed in 4.0.102023-08-09
CVE-2023-37862 [HIGH] CWE-862 CVE-2023-37862: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
nvd
CVE-2023-37864HIGHCVSS 7.2fixed in 4.0.102023-08-09
CVE-2023-37864 [HIGH] CWE-494 CVE-2023-37864: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNM
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
nvd
CVE-2023-37861HIGHCVSS 8.8fixed in 4.0.102023-08-09
CVE-2023-37861 [HIGH] CWE-78 CVE-2023-37861: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote at
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
nvd
CVE-2023-37857HIGHCVSS 7.2fixed in 4.0.102023-08-09
CVE-2023-37857 [LOW] CWE-798 CVE-2023-37857: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote a
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.
nvd
CVE-2023-37855MEDIUMCVSS 4.3fixed in 4.0.102023-08-09
CVE-2023-37855 [MEDIUM] CWE-610 CVE-2023-37855: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
nvd
CVE-2023-37856MEDIUMCVSS 4.3fixed in 4.0.102023-08-09
CVE-2023-37856 [MEDIUM] CWE-610 CVE-2023-37856: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
nvd
CVE-2023-37858MEDIUMCVSS 4.9fixed in 4.0.102023-08-09
CVE-2023-37858 [MEDIUM] CWE-311 CVE-2023-37858: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote a
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
nvd
CVE-2023-3572CRITICALCVSS 9.9fixed in 4.0.102023-08-08
CVE-2023-3572 [CRITICAL] CWE-78 CVE-2023-3572: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
nvd
CVE-2023-3571HIGHCVSS 8.8fixed in 4.0.102023-08-08
CVE-2023-3571 [HIGH] CWE-78 CVE-2023-3571: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
nvd
CVE-2023-3573HIGHCVSS 8.8fixed in 4.0.102023-08-08
CVE-2023-3573 [HIGH] CWE-78 CVE-2023-3573: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
nvd
CVE-2023-3570HIGHCVSS 8.8fixed in 4.0.102023-08-08
CVE-2023-3570 [HIGH] CWE-78 CVE-2023-3570: In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
nvd