VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Aug 2, 2024

PHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panels

CVE-2023-37859

Description

Remote attacker with SNMPv2 read/write community string can execute arbitrary commands as root on Phoenix Contact WP 6xxx web panels before 4.0.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Remote attacker with SNMPv2 read/write community string can execute arbitrary commands as root on Phoenix Contact WP 6xxx web panels before 4.0.10.

Vulnerability

The SNMP daemon on Phoenix Contact WP 6xxx series web panels prior to version 4.0.10 runs with root privileges. This allows a remote attacker who knows the SNMPv2 read/write community string to execute arbitrary system commands as root via crafted SNMP set requests [1].

Exploitation

An attacker must have network access to the device and possess the SNMPv2 read/write community string (e.g., obtained through other vulnerabilities or brute-force). The attacker sends specially crafted SNMP set packets to the daemon, which executes the embedded command with root privileges [1].

Impact

Successful exploitation grants the attacker full root access to the device, enabling complete compromise of confidentiality, integrity, and availability. The attacker can execute arbitrary OS commands, install malicious software, and pivot to other systems on the network [1].

Mitigation

Phoenix Contact released firmware version 4.0.10 to fix this vulnerability. Users should update to this version or later. As a workaround, restrict SNMP access via firewall rules and change the default community strings, though this may not fully mitigate if the community string is compromised [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.