Impact
The CHARX JupiCore service in Phoenix Contact charging point controllers suffers from a missing authentication weakness (CWE-306). An attacker who can reach the service can reconfigure charging points without credentials, potentially exposing charging point unique identifiers, causing denial‑of‑service conditions, and tampering with configuration files. The impact is loss of confidentiality for UIDs, integrity of configuration data, and availability of the charging infrastructure.
Affected Systems
Affected models are the Phoenix Contact CHARX SEC‑3000, SEC‑3050, SEC‑3100 and SEC‑3150. No explicit firmware or software version information was supplied, so any device running the JupiCore service is potentially vulnerable. The CPE strings for these models confirm the scope of impact.
Risk and Exploitability
The CVSS score of 8.8 judges the severity as high. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; an adversary would need network access to the JupiCore service, which is typically exposed on a local or wide‑area network. No additional prerequisites are described, so the vulnerability appears to be reachable by any host that can connect to the service's port.
OpenCVE Enrichment