CVE-2024-26004: PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX Series
Published Mar 12, 2024
·Updated
An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
Affected Software
9 affected components
Phoenix Contact CHARX Series
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.5.1
Phoenixcontact Charx Sec-3150
Event History
Mar 12, 2024
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-26004?
CVE-2024-26004 has a high severity rating due to its potential to cause a denial of service for control agents.
2
How do I fix CVE-2024-26004?
To fix CVE-2024-26004, update the firmware of the affected Phoenixcontact CHARX devices to version 1.5.1 or later.
3
What devices are affected by CVE-2024-26004?
CVE-2024-26004 affects Phoenixcontact CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 firmware versions lower than 1.5.1.
4
What type of attack does CVE-2024-26004 enable?
CVE-2024-26004 enables unauthenticated remote denial of service attacks on affected control agents.
5
Can CVE-2024-26004 be exploited locally?
CVE-2024-26004 cannot be exploited locally as it specifically allows remote attackers to exploit the vulnerability.