CVE-2025-24002
Estado: AnalizadaMedia (5.3)—
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-24002",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-24002",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-07-08T13:39:22.906184Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Phoenix Contact",
"product": "CHARX SEC-3150",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "1.6.5"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Phoenix Contact",
"product": "CHARX SEC-3100",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "1.6.5"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Phoenix Contact",
"product": "CHARX SEC-3050",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "1.6.5"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Phoenix Contact",
"product": "CHARX SEC-3000",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "1.6.5"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-07-08T07:15:23.473",
"references": [
{
"url": "https://certvde.com/en/advisories/VDE-2025-014",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog."
},
{
"lang": "es",
"value": "Un atacante remoto no autenticado puede usar mensajes MQTT para bloquear un servicio en estaciones de carga que cumplen con la Ley de Calibración Alemana, lo que genera una denegación de servicio temporal para estas estaciones hasta que sean reiniciadas por el organismo de control."
}
],
"lastModified": "2026-06-17T08:57:52.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6338C05A-3F0E-408E-98B1-51B2EAE05F5B",
"versionEndIncluding": "1.6.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:phoenixcontact:charx_sec-3000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D1095269-9D5A-4557-BA9D-33B49AAA339F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC6EA57F-57E6-437F-8035-3B714A4E824C",
"versionEndIncluding": "1.6.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:phoenixcontact:charx_sec-3050:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "775BA5ED-968B-4759-BA39-50F9EAB29169"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "160F031E-81BB-466B-808D-6BF46D28BD17",
"versionEndIncluding": "1.6.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:phoenixcontact:charx_sec-3100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F498BFB3-3C39-4F0B-9775-0B4F891D866C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B0E8722-3BCD-4360-BF23-7BC020A28D51",
"versionEndIncluding": "1.6.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:phoenixcontact:charx_sec-3150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "32916BED-0241-4787-960C-7A4E8E1DDED7"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}