ZDI-24-859: (Pwn2Own) Phoenix Contact CHARX SEC-3100 MTQQ Protocol JSON Parsing Type Confusion Information Disclosure Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3100 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-26000.
Affected Software
1 affected component
Phoenix Contact CHARX SEC-3100
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-859?
The severity of ZDI-24-859 is rated at 4.3 on the CVSS scale.
2
What devices are affected by ZDI-24-859?
ZDI-24-859 affects the Phoenix Contact CHARX SEC-3100 devices.
3
Is authentication required to exploit ZDI-24-859?
No, authentication is not required to exploit ZDI-24-859.
4
What information can be disclosed due to ZDI-24-859?
ZDI-24-859 allows network-adjacent attackers to disclose sensitive information.
5
How can I protect my Phoenix Contact CHARX SEC-3100 devices from ZDI-24-859?
To protect against ZDI-24-859, ensure that your devices are updated and follow security best practices.