Description
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
|
History
Thu, 30 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. | |
| Title | File Upload vulnerability | |
| First Time appeared |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-30T06:49:34.687Z
Reserved: 2026-05-05T10:48:08.226Z
Link: CVE-2026-44097
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-434
Unrestricted Upload of File with Dangerous Type