ZDI-CAN-24095: ZDI-24-866: (Pwn2Own) Phoenix Contact CHARX SEC-3100 CANopenDevice Null Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3100 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-26004.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24095?
ZDI-CAN-24095 has been assigned a CVSS rating of 6.5, indicating a moderate severity level.
How do I fix ZDI-CAN-24095?
To mitigate ZDI-CAN-24095, apply the latest firmware updates provided by Phoenix Contact for CHARX SEC-3100 devices.
What type of attack does ZDI-CAN-24095 allow?
ZDI-CAN-24095 allows network-adjacent attackers to create a denial-of-service condition on affected installations.
Is authentication required to exploit ZDI-CAN-24095?
No, authentication is not required to exploit ZDI-CAN-24095.
Which devices are affected by ZDI-CAN-24095?
ZDI-CAN-24095 specifically affects installations of Phoenix Contact CHARX SEC-3100 devices.