CVE-2024-28134

An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected. 
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3050:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3150:-:*:*:*:*:*:*:*

History

23 Jan 2025, 18:53

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2024-019 - () https://cert.vde.com/en/advisories/VDE-2024-019 - Third Party Advisory
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : unknown
CPE cpe:2.3:h:phoenixcontact:charx_sec-3000:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3100:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3150:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3050:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:*
CWE CWE-319
First Time Phoenixcontact charx Sec-3100 Firmware
Phoenixcontact charx Sec-3050 Firmware
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3000 Firmware
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3150 Firmware
Phoenixcontact charx Sec-3000
Phoenixcontact
Phoenixcontact charx Sec-3150

14 May 2024, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:16

Updated : 2025-01-23 18:53


NVD link : CVE-2024-28134

Mitre link : CVE-2024-28134


JSON object : View

Products Affected

phoenixcontact

  • charx_sec-3000
  • charx_sec-3050_firmware
  • charx_sec-3150
  • charx_sec-3150_firmware
  • charx_sec-3100
  • charx_sec-3050
  • charx_sec-3000_firmware
  • charx_sec-3100_firmware
CWE

No CWE.