It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. | |
| Title | Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers | |
| First Time appeared |
Phoenix Contact
Phoenix Contact charx Sec-3000 Firmware Phoenix Contact charx Sec-3050 Firmware Phoenix Contact charx Sec-3100 Firmware Phoenix Contact charx Sec-3150 Firmware |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:o:phoenix_contact:charx_sec-3000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec-3050_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec-3100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec-3150_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact charx Sec-3000 Firmware Phoenix Contact charx Sec-3050 Firmware Phoenix Contact charx Sec-3100 Firmware Phoenix Contact charx Sec-3150 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-06-03T10:16:16.992Z
Reserved: 2026-04-16T06:00:17.600Z
Link: CVE-2026-41032
No data.
Status : Received
Published: 2026-06-03T11:16:19.540
Modified: 2026-06-03T11:16:19.540
Link: CVE-2026-41032
No data.
OpenCVE Enrichment
No data.
Weaknesses