CVE-2024-26001

EUVD-2024-23297
An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
phoenixcontactcharx_sec-3000_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3050_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3100_firmware
𝑥
< 1.5.1
phoenixcontactcharx_sec-3150_firmware
𝑥
< 1.5.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
phoenixcontactcharx_sec_3000
𝑥
≤ 1.5.0
ADP
phoenixcontactcharx_sec_3050
𝑥
≤ 1.5.0
ADP
phoenixcontactcharx_sec_3100
𝑥
≤ 1.5.0
ADP
phoenixcontactcharx_sec_3150
𝑥
≤ 1.5.0
ADP