Aug. 8, 2023, 7:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.

access command command injection configuration contacts cve device http injection low may panels phoenix privileges request series web

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior SecOps Security Architect

@ SGS | Madrid, Spain

Auditeur(trice) de configuration et d’architecture - Cybersécurité - Toulouse

@ Sopra Steria | Colomiers, France

Cybersecurity - staż SantanderTech

@ Santander | Wrocław