8.8
CVE-2025-25268
- EPSS 0.03%
- Veröffentlicht 08.07.2025 07:00:27
- Zuletzt bearbeitet 11.07.2025 14:37:03
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Charx Sec-3000 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3050 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3100 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3150 Firmware Version < 1.7.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.