VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panels

CVE-2023-37860

Description

An unauthenticated remote attacker can obtain the SNMPv2 read-write community string from Phoenix Contact WP 6xxx web panels before version 4.0.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated remote attacker can obtain the SNMPv2 read-write community string from Phoenix Contact WP 6xxx web panels before version 4.0.10.

Vulnerability

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10, the SNMPv2 daemon exposes the read-write community string to a remote unauthenticated attacker [1]. This occurs because the device does not properly protect the community string in network communications, allowing it to be retrieved without authentication or prior access.

Exploitation

An attacker with network access to the affected web panel can obtain the SNMPv2 read-write community string by sending unauthenticated requests to the SNMP daemon. No prior authentication or user interaction is required [1]. The attacker only needs to be able to reach the device over the network.

Impact

Successful exploitation allows the attacker to gain the read-write community string for SNMPv2, enabling them to read and modify SNMP-managed objects on the device. This can lead to disclosure of device configuration information and potentially further compromise of the device's integrity and availability [1].

Mitigation

The vulnerability is fixed in version 4.0.10 of the WP 6xxx series firmware. Users should update to this version or later as soon as possible to mitigate the risk [1]. No workaround is mentioned in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • PHOENIX CONTACT/WP 6070-WVPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6101-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6121-WXPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6156-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6185-WHPSv5
    Range: 0
  • PHOENIX CONTACT/WP 6215-WHPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.