Impact
The credential for the local account "user-app" is written to log files in cleartext. A local attacker who can read the logs can obtain these credentials and then authenticate to the device through SSH using that account, potentially allowing them to interrupt charging operations and access restricted functions. This flaw features a medium CVSS score of 5.8 and is a classic example of information exposure via logs (CWE‑532).
Affected Systems
The affected devices are Phoenix Contact CHARX SEC‑3000, SEC‑3050, SEC‑3100, and SEC‑3150. Version details are not supplied in the current advisory, so all current releases of these products are presumed vulnerable until a fix is issued.
Risk and Exploitability
Given the low EPSS score (<1%) and the absence of listing in CISA’s KEV catalog, the likelihood of exploitation in the wild appears limited. Nonetheless, the vulnerability remains exploitable by any local user with read access to the log files, who could then leverage the exposed password to gain SSH access and disrupt charging. The CVSS score of 5.8 reflects a moderate severity, emphasizing that remediation is advisable to prevent potential operational impact.
OpenCVE Enrichment