CVE-2023-37860: PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37860?
CVE-2023-37860 is a vulnerability in PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, where a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.
How severe is CVE-2023-37860?
CVE-2023-37860 has a severity rating of 7.5 (high).
What is affected by CVE-2023-37860?
PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 are affected by CVE-2023-37860.
How can an attacker exploit CVE-2023-37860?
An attacker can exploit CVE-2023-37860 by remotely and without authentication obtaining the r/w community string of the SNMPv2 daemon.
Is there a fix available for CVE-2023-37860?
Yes, updating to version 4.0.10 or later of PHOENIX CONTACTs WP 6xxx series web panels will fix CVE-2023-37860.