PT-2024-7101 · Phoenix Contact · Phoenix Contact Charx Sec-3000

·

CVE-2024-6788

·

Published

2024-08-13

·

Updated

2025-08-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Phoenix Contact CHARX SEC-3000 versions up to 1.6.2
Description A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user user-app to the default password. The issue is related to insecure default resource initialization.
Recommendations For Phoenix Contact CHARX SEC-3000 versions up to 1.6.2, update the firmware to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the firmware update feature on the LAN interface to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08368
CVE-2024-6788

Affected Products

Phoenix Contact Charx Sec-3000