Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Phoenix_Contact Charx_Sec_3150
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
|
1.0.0
|
1.9.1
|
|
Phoenix_Contact Charx_Sec_3100
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
|
1.0.0
|
1.9.1
|
|
Phoenix_Contact Charx_Sec_3050
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
|
1.0.0
|
1.9.1
|
|
Phoenix_Contact Charx_Sec_3000
cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
|
1.0.0
|
1.9.1
|