CVE-2024-26000

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack.The brute force attack is not always successful because of memory randomization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CERTVDECNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
phoenixcontactcharx_sec-3000_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3050_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3100_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3150_firmware
𝑥
< 1.5.1
𝑥
= Vulnerable software versions