PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity check
CVE-2023-37864
7.2HIGH
What is CVE-2023-37864?
A vulnerability exists in PHOENIX CONTACT's WP 6xxx series web panels which allows a remote attacker with SNMPv2 write privileges to execute specially crafted SNMP requests. These requests could enable the attacker to gain full access to the devices, compromising their integrity and security. Users are advised to update to version 4.0.10 or later to mitigate this risk.
Affected Version(s)
WP 6070-WVPS 0 < 4.0.10
WP 6101-WXPS 0 < 4.0.10
WP 6121-WXPS 0 < 4.0.10