PHOENIX CONTACT: Command Injection in WP 6xxx Web panels
Published Aug 8, 2023
8.8
HIGHCVSS 3.1
EPSS 1.24%
Description
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
Affected products
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Phoenix Contact | WP 6070-Wvps | unaffected |
| ||||||
| Phoenix Contact | WP 6101-Wxps | unaffected |
| ||||||
| Phoenix Contact | WP 6121-Wxps | unaffected |
| ||||||
| Phoenix Contact | WP 6156-Whps | unaffected |
| ||||||
| Phoenix Contact | WP 6185-Whps | unaffected |
| ||||||
| Phoenix Contact | WP 6215-Whps | unaffected |
|
Configuration 1
- < 4.0.10
Running on/with
- n/a
Configuration 2
- < 4.0.10
Running on/with
- n/a
Configuration 3
- < 4.0.10
Running on/with
- n/a
Configuration 4
- < 4.0.10
Running on/with
- n/a
Configuration 5
- < 4.0.10
Running on/with
- n/a
Configuration 6
- < 4.0.10
Running on/with
- n/a
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
-
- Version 0StatusaffectedConstraints<4.0.10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Phoenixcontact | WP 6070-Wvps | unaffected |
| ||||||
| Phoenixcontact | WP 6101-Wxps | unaffected |
| ||||||
| Phoenixcontact | WP 6121-Wxps | unaffected |
| ||||||
| Phoenixcontact | WP 6156-Whps | unaffected |
| ||||||
| Phoenixcontact | WP 6185-Whps | unaffected |
| ||||||
| Phoenixcontact | WP 6215-Whps | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://cert.vde.com/en/advisories/VDE-2023-018/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2023-018/ | Third Party Advisory |
Change history (0)
No recorded changes yet.