ZDI-CAN-23239: ZDI-24-859: (Pwn2Own) Phoenix Contact CHARX SEC-3100 MTQQ Protocol JSON Parsing Type Confusion Information Disclosure Vulnerability
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3100 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-26000.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23239?
The severity of ZDI-CAN-23239 is rated as 4.3 according to the CVSS.
What devices are affected by ZDI-CAN-23239?
ZDI-CAN-23239 affects Phoenix Contact CHARX SEC-3100 devices.
Can ZDI-CAN-23239 be exploited without authentication?
Yes, ZDI-CAN-23239 can be exploited without requiring authentication.
What type of attack does ZDI-CAN-23239 involve?
ZDI-CAN-23239 involves a vulnerability that allows network-adjacent attackers to disclose sensitive information.
How can I mitigate the risks associated with ZDI-CAN-23239?
To mitigate the risks associated with ZDI-CAN-23239, ensure to update your Phoenix Contact CHARX SEC-3100 devices to the latest firmware that addresses this vulnerability.