Phoenixcontact Charx Sec-3100 Firmware vulnerabilities

29 known vulnerabilities affecting phoenixcontact/charx_sec-3100_firmware.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH17MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2024-25999HIGHCVSS 7.8fixed in 1.5.12024-03-12
CVE-2024-25999 [HIGH] CWE-20 CVE-2024-25999: An unauthenticated local attacker can perform a privilege escalation due to improper input validatio An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
nvd
CVE-2024-26004HIGHCVSS 7.5fixed in 1.5.12024-03-12
CVE-2024-26004 [HIGH] CWE-824 CVE-2024-26004: An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
nvd
CVE-2024-26000HIGHCVSS 7.5fixed in 1.5.12024-03-12
CVE-2024-26000 [MEDIUM] CWE-125 CVE-2024-26000: An unauthenticated remote attacker can read memory out of bounds due to improper input validation in An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
nvd
CVE-2024-25998HIGHCVSS 7.3fixed in 1.5.12024-03-12
CVE-2024-25998 [HIGH] CWE-77 CVE-2024-25998: An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
nvd
CVE-2024-26002HIGHCVSS 7.8fixed in 1.5.12024-03-12
CVE-2024-26002 [HIGH] CWE-20 CVE-2024-26002: An improper input validation in the Qualcom plctool allows a local attacker with low privileges to g An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
nvd
CVE-2024-26288HIGHCVSS 8.7fixed in 1.5.12024-03-12
CVE-2024-26288 [HIGH] CWE-319 CVE-2024-26288: An unauthenticated remote attacker can influence the communication due to the lack of encryption of An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
nvd
CVE-2024-25997MEDIUMCVSS 5.3fixed in 1.5.12024-03-12
CVE-2024-25997 [MEDIUM] CWE-20 CVE-2024-25997: An unauthenticated remote attacker can perform a log injection due to improper input validation. Onl An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
nvd
CVE-2024-26005MEDIUMCVSS 4.8fixed in 1.5.12024-03-12
CVE-2024-26005 [MEDIUM] CWE-459 CVE-2024-26005: An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup d An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.
nvd
CVE-2024-25994MEDIUMCVSS 5.3fixed in 1.5.12024-03-12
CVE-2024-25994 [MEDIUM] CWE-434 CVE-2024-25994: An unauthenticated remote attacker can upload a arbitrary script file due to improper input validati An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
nvd