Phoenix Contact Charx Sec-3100 vulnerabilities

30 known vulnerabilities affecting phoenix_contact/charx_sec-3100.

Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH19MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2024-26000HIGHCVSS 7.5≤ 1.5.02024-03-12
CVE-2024-26000 [MEDIUM] CWE-125 CVE-2024-26000: An unauthenticated remote attacker can read memory out of bounds due to improper input validation in An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
cvelistv5nvd
CVE-2024-26003HIGHCVSS 7.5≤ 1.5.02024-03-12
CVE-2024-26003 [HIGH] CWE-125 CVE-2024-26003: An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may p An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.
cvelistv5nvd
CVE-2024-26288HIGHCVSS 8.7≤ 1.5.02024-03-12
CVE-2024-26288 [HIGH] CWE-319 CVE-2024-26288: An unauthenticated remote attacker can influence the communication due to the lack of encryption of An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
cvelistv5nvd
CVE-2024-25999HIGHCVSS 7.8≤ 1.5.02024-03-12
CVE-2024-25999 [HIGH] CWE-20 CVE-2024-25999: An unauthenticated local attacker can perform a privilege escalation due to improper input validatio An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
cvelistv5nvd
CVE-2024-26004HIGHCVSS 7.5≤ 1.5.02024-03-12
CVE-2024-26004 [HIGH] CWE-824 CVE-2024-26004: An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
cvelistv5nvd
CVE-2024-25998HIGHCVSS 7.3≤ 1.5.02024-03-12
CVE-2024-25998 [HIGH] CWE-77 CVE-2024-25998: An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
cvelistv5nvd
CVE-2024-26002HIGHCVSS 7.8≤ 1.5.02024-03-12
CVE-2024-26002 [HIGH] CWE-20 CVE-2024-26002: An improper input validation in the Qualcom plctool allows a local attacker with low privileges to g An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
cvelistv5nvd
CVE-2024-25994MEDIUMCVSS 5.3≤ 1.5.02024-03-12
CVE-2024-25994 [MEDIUM] CWE-434 CVE-2024-25994: An unauthenticated remote attacker can upload a arbitrary script file due to improper input validati An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
cvelistv5nvd
CVE-2024-25997MEDIUMCVSS 5.3≤ 1.5.02024-03-12
CVE-2024-25997 [MEDIUM] CWE-20 CVE-2024-25997: An unauthenticated remote attacker can perform a log injection due to improper input validation. Onl An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
cvelistv5nvd
CVE-2024-26005MEDIUMCVSS 4.8≤ 1.5.02024-03-12
CVE-2024-26005 [MEDIUM] CWE-459 CVE-2024-26005: An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup d An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.
cvelistv5nvd
Phoenix Contact Charx Sec-3100 vulnerabilities | cvebase