CVE-2024-26288: PHOENIX CONTACT: Lack of SSL support in CHARX Series
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26288?
CVE-2024-26288 has been rated as a significant vulnerability due to its potential for unauthorized data manipulation during transmission.
How do I fix CVE-2024-26288?
To remediate CVE-2024-26288, upgrade to the latest firmware version above 1.5.1 for affected Phoenix Contact CHARX devices.
Who is affected by CVE-2024-26288?
CVE-2024-26288 affects users of the Phoenix Contact CHARX Sec-3000, Sec-3050, Sec-3100, and Sec-3150 firmware versions prior to 1.5.1.
What type of attack does CVE-2024-26288 expose systems to?
CVE-2024-26288 exposes systems to man-in-the-middle (MITM) attacks due to the lack of encryption of sensitive communications.
Can I continue to use affected devices with CVE-2024-26288?
Using affected devices with CVE-2024-26288 without remediation poses a security risk and is not recommended.