PT-2024-7101 · Phoenix Contact · Phoenix Contact Charx Sec-3000

Alex Olson

+4

·

Published

2024-08-13

·

Updated

2025-08-22

·

CVE-2024-6788

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Phoenix Contact CHARX SEC-3000 versions up to 1.6.2
Description A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user user-app to the default password. The issue is related to insecure default resource initialization.
Recommendations For Phoenix Contact CHARX SEC-3000 versions up to 1.6.2, update the firmware to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the firmware update feature on the LAN interface to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-08368
CVE-2024-6788

Affected Products

Phoenix Contact Charx Sec-3000