TROYANOSYVIRUS
Volver a CVEs

CVE-2023-3572

CRITICAL
10.0

Descripcion

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.

Detalles CVE

Puntuacion CVSS v3.110.0
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/8/2023
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

phoenixcontact:wp_6070-wvpsphoenixcontact:wp_6070-wvps_firmwarephoenixcontact:wp_6101-wxpsphoenixcontact:wp_6101-wxps_firmwarephoenixcontact:wp_6121-wxpsphoenixcontact:wp_6121-wxps_firmwarephoenixcontact:wp_6156-whpsphoenixcontact:wp_6156-whps_firmwarephoenixcontact:wp_6185-whpsphoenixcontact:wp_6185-whps_firmwarephoenixcontact:wp_6215-whpsphoenixcontact:wp_6215-whps_firmware

Debilidades (CWE)

CWE-78

Referencias

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.