CVE-2024-6788
EUVD-2024-4781813.08.2024, 14:15
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| phoenixcontact | charx_sec-3000_firmware | 𝑥 < 1.6.3 |
| phoenixcontact | charx_sec-3050_firmware | 𝑥 < 1.6.3 |
| phoenixcontact | charx_sec-3100_firmware | 𝑥 < 1.6.3 |
| phoenixcontact | charx_sec-3150_firmware | 𝑥 < 1.6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration