PT-2024-7101 · Phoenix Contact · Phoenix Contact Charx Sec-3000
Alex Olson
+4
·
Published
2024-08-13
·
Updated
2025-08-22
·
CVE-2024-6788
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phoenix Contact CHARX SEC-3000 versions up to 1.6.2
Description
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user
user-app to the default password. The issue is related to insecure default resource initialization.Recommendations
For Phoenix Contact CHARX SEC-3000 versions up to 1.6.2, update the firmware to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the firmware update feature on the LAN interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phoenix Contact Charx Sec-3000