CVE-2024-3913 MEDIUM

CVE-2024-3913: Phoenix Contact: Start sequence allows attack during the boot process

Vendor Phoenix Contact
Product CHARX SEC-3000 (1139022)
Weakness CWE-552 · Files accessible externally
Published August 13, 2024
Last update January 29, 2025

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.

Key dates

02Disclosure timeline

August 13, 2024 CVE published
January 29, 2025 Record updated