← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.00

ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.

Číst originál na Zero Day Initiative →

2 zprávy z 2 zdrojů · první 3. 6. 12:01 · poslední 30. 7. 07:00 CZ · EN/orig

Phoenix Contact US DE

tg: zranitelnost tp: průmyslové systémy

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-41032 7.5 3.1 · CERTVDE 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 6.5.

Jak se o tom psalo 2

  1. · Zero Day Initiative US nadpis události

    ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.

  2. · CERT@VDE DE

    Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

    [VDE-2026-060] VDE-2026-060: A unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers has been discovered.