CVE-2024-26000: PHOENIX CONTACT: Out of bounds read only memory access
An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26000?
CVE-2024-26000 is classified as a high severity vulnerability due to its ability to allow unauthenticated remote attackers to read memory out of bounds.
How do I fix CVE-2024-26000?
To fix CVE-2024-26000, it is recommended to update the firmware of affected devices to the latest version beyond 1.5.1.
Which devices are affected by CVE-2024-26000?
CVE-2024-26000 affects the Phoenix Contact CHARX SEC-3000, 3050, 3100, and 3150 firmware versions prior to 1.5.1.
What are the potential impacts of CVE-2024-26000?
The impacts of CVE-2024-26000 include unauthorized access to sensitive memory information, potentially leading to system compromise.
Is there a workaround for CVE-2024-26000?
Currently, no specific workarounds are recommended for CVE-2024-26000; updating to a secure firmware version is the primary mitigation.