Phoenixcontact
Phoenixcontact Charx Sec-3150 Firmware: vulnerabilidades y CVE
Phoenixcontact Charx Sec-3150 Firmware tiene 29 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-25271 | Alta (8.8) | 0.34% | — | 8 jul 2025 | An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. |
| CVE-2025-25270 | Crítica (9.8) | 0.73% | — | 8 jul 2025 | An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations. |
| CVE-2025-25269 | Alta (8.4) | 0.29% | — | 8 jul 2025 | An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation. |
| CVE-2025-25268 | Alta (8.8) | 0.35% | — | 8 jul 2025 | An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication. |
| CVE-2025-24006 | Alta (7.8) | 0.12% | — | 8 jul 2025 | A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root. |
| CVE-2025-24005 | Alta (7.8) | 0.14% | — | 8 jul 2025 | A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation. |
| CVE-2025-24004 | Media (5.2) | 0.18% | — | 8 jul 2025 | A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the… |
| CVE-2025-24003 | Alta (8.2) | 0.37% | — | 8 jul 2025 | An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and… |
| CVE-2025-24002 | Media (5.3) | 0.40% | — | 8 jul 2025 | An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got… |
| CVE-2024-6788 | Crítica (9.8) | 0.50% | — | 13 ago 2024 | A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password. |
| CVE-2024-3913 | Media (5.3) | 0.51% | — | 13 ago 2024 | An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. |
| CVE-2024-28137 | Alta (7.8) | 0.25% | — | 14 may 2024 | A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability. |
| CVE-2024-28136 | Alta (7.8) | 0.75% | — | 14 may 2024 | A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service. |
| CVE-2024-28135 | Media (5) | 1.3% | — | 14 may 2024 | A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. |
| CVE-2024-28134 | Alta (7) | 0.49% | — | 14 may 2024 | An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive… |
| CVE-2024-28133 | Alta (7.8) | 0.38% | — | 14 may 2024 | A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. |
| CVE-2024-26288 | Alta (8.7) | 0.31% | — | 12 mar 2024 | An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. |
| CVE-2024-26005 | Media (4.8) | 0.62% | — | 12 mar 2024 | An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. |
| CVE-2024-26004 | Alta (7.5) | 1.0% | — | 12 mar 2024 | An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality. |
| CVE-2024-26003 | Alta (7.5) | 1.2% | — | 12 mar 2024 | An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. |
| CVE-2024-26002 | Alta (7.8) | 0.26% | — | 12 mar 2024 | An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. |
| CVE-2024-26001 | Crítica (9.8) | 0.87% | — | 12 mar 2024 | An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. |
| CVE-2024-26000 | Alta (7.5) | 0.81% | — | 12 mar 2024 | An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. |
| CVE-2024-25999 | Alta (7.8) | 0.41% | — | 12 mar 2024 | An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. |
| CVE-2024-25998 | Alta (7.3) | 1.5% | — | 12 mar 2024 | An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. |
| CVE-2024-25997 | Media (5.3) | 0.69% | — | 12 mar 2024 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected. |
| CVE-2024-25996 | Crítica (9.8) | 0.39% | — | 12 mar 2024 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. |
| CVE-2024-25995 | Crítica (9.8) | 1.4% | — | 12 mar 2024 | An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. |
| CVE-2024-25994 | Media (5.3) | 0.73% | — | 12 mar 2024 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phoenixcontact
Charx Sec-3050 Firmware · 29Charx Sec-3000 Firmware · 29Charx Sec-3100 Firmware · 29FL Mguard Rs4004 Tx/dtx Firmware · 16FL Mguard Rs4004 Tx/dtx VPN Firmware · 16FL Mguard Gt/gt VPN Firmware · 15FL Mguard Pci4000 Firmware · 15FL Mguard Core TX VPN Firmware · 15FL Mguard Delta Tx/tx VPN Firmware · 15FL Mguard Delta Tx/tx Firmware · 15FL Mguard Centerport Vpn-1000 Firmware · 15FL Mguard Core TX Firmware · 15