CVE-2024-6788

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user user-app to the default password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CERTVDECNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
phoenixcontactcharx_sec-3000_firmware
𝑥
< 1.6.3
phoenixcontactcharx_sec-3050_firmware
𝑥
< 1.6.3
phoenixcontactcharx_sec-3100_firmware
𝑥
< 1.6.3
phoenixcontactcharx_sec-3150_firmware
𝑥
< 1.6.3
𝑥
= Vulnerable software versions