Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gadha

Researcher fromTrend Micro's Zero Day Initiative
#26304of 53,625
9.8Total CVSS
Vulnerabilities · 1
PT-2024-7101
9.8
2024-08-13
Phoenix Contact · Phoenix Contact Charx Sec-3000 · CVE-2024-6788
**Name of the Vulnerable Software and Affected Versions** Phoenix Contact CHARX SEC-3000 versions up to 1.6.2 **Description** A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user `user-app` to the default password. The issue is related to insecure default resource initialization. **Recommendations** For Phoenix Contact CHARX SEC-3000 versions up to 1.6.2, update the firmware to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the firmware update feature on the LAN interface to minimize the risk of exploitation.