PT-2024-21273 · Phoenix Contact · Charx Sec-3100

Carlo Meijer

+1

·

Published

2024-03-12

·

Updated

2025-01-24

·

CVE-2024-26000

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Phoenix Contact CHARX SEC-3100 (affected versions not specified)
Description An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-26000
ZDI-24-859

Affected Products

Charx Sec-3100