{"document":{"acknowledgments":[{"organization":"CERTVDE","summary":"coordination.","urls":["https://certvde.com/en/"]},{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Multiple vulnerabilities in the firmware of CHARX SEC-3xxx charging controllers have been discovered.","title":"Summary"},{"category":"description","text":"The vulnerabilities can lead to a total loss of confidentiality, integrity and availability of the devices.","title":"Impact"},{"category":"description","text":"Affected charging controllers are designed and developed for the use in closed industrial networks. Phoenix Contact therefore strongly recommends using the devices exclusively in closed networks and protected by a suitable firewall.","title":"Mitigation"},{"category":"description","text":"Phoenix Contact strongly recommends to upgrade to firmware version 1.7.3 which fixes vulnerabilities CVE-2025-24005 and CVE-2025-24006. The vulnerabilities CVE-2025-24002, CVE-2025-24003 and CVE-2025-24004 affect the Eichrecht functionality in FW <=1.6.5 and in the meantime there is no vendor fix planned for these issues.","title":"Remediation"},{"category":"general","text":"For general information and recommendations on security measures to protect network-enabled devices, refer to the application note: [Application Note Security](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf).","title":"General Recommendation"},{"category":"description","text":"CHARX SEC EVSE charging controller","title":"Product Description"}],"publisher":{"category":"vendor","contact_details":"psirt@phoenixcontact.com","name":"Phoenix Contact GmbH & Co. KG","namespace":"https://phoenixcontact.com/psirt"},"references":[{"category":"external","summary":"PCSA-2025-00001","url":"https://phoenixcontact.com/psirt"},{"category":"external","summary":"Phoenix Contact advisory overview at CERT@VDE","url":"https://certvde.com/de/advisories/vendor/phoenixcontact/"},{"category":"self","summary":"VDE-2025-014: Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers - HTML","url":"https://certvde.com/en/advisories/VDE-2025-014"},{"category":"self","summary":"VDE-2025-014: Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers - CSAF","url":"https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-014.json"},{"category":"external","summary":"Phoenix Contact application note","url":"https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf"}],"title":"Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers","tracking":{"aliases":["VDE-2025-014","PCSA-2025-00001"],"current_release_date":"2025-07-08T10:00:00.000Z","generator":{"date":"2025-07-01T07:46:11.590Z","engine":{"name":"Secvisogram","version":"2.5.27"}},"id":"VDE-2025-014","initial_release_date":"2025-07-08T10:00:00.000Z","revision_history":[{"date":"2025-07-08T10:00:00.000Z","number":"1","summary":"Initial Revision"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"CHARX SEC-3150","product":{"name":"CHARX SEC-3150","product_id":"CSAFPID-11001"}},{"category":"product_name","name":"CHARX SEC-3100","product":{"name":"CHARX SEC-3150","product_id":"CSAFPID-11002"}},{"category":"product_name","name":"CHARX SEC-3050","product":{"name":"CHARX SEC-3050","product_id":"CSAFPID-11003"}},{"category":"product_name","name":"CHARX SEC-3000","product":{"name":"CHARX SEC-3000","product_id":"CSAFPID-11004"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<FW 1.7.3","product":{"name":"Firmware < FW 1.7.3","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"FW 1.7.3","product":{"name":"Firmware 1.7.3","product_id":"CSAFPID-22001"}},{"category":"product_version_range","name":"<=FW 1.6.5","product":{"name":"Firmware <= FW 1.6.5","product_id":"CSAFPID-21002"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Phoenix Contact"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004"],"summary":"Fixed products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"FW <1.7.3 installed on CHARX SEC-3150","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"FW <1.7.3 installed on CHARX SEC-3100","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"FW <1.7.3 installed on CHARX SEC-3050","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"FW <1.7.3 installed on CHARX SEC-3000","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"FW 1.7.3 installed on CHARX SEC-3150","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"FW 1.7.3 installed on CHARX SEC-3100","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"FW 1.7.3 installed on CHARX SEC-3050","product_id":"CSAFPID-32003"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"FW 1.7.3 installed on CHARX SEC-3000","product_id":"CSAFPID-32004"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"FW <=1.6.5 installed on CHARX SEC-3150","product_id":"CSAFPID-31005"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"FW <=1.6.5 installed on CHARX SEC-3100","product_id":"CSAFPID-31006"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"FW <=1.6.5 installed on CHARX SEC-3050","product_id":"CSAFPID-31007"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"FW <=1.6.5 installed on CHARX SEC-3000","product_id":"CSAFPID-31008"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11004"}]},"vulnerabilities":[{"acknowledgments":[{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"cve":"CVE-2025-24002","cwe":{"id":"CWE-20","name":"Improper Input Validation"},"notes":[{"category":"summary","text":"An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]},"remediations":[{"category":"mitigation","details":"This product was designed for use in closed industrial networks. Phoenix Contact strongly recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf). ","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]}],"title":"CVE-2025-24002"},{"acknowledgments":[{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"cve":"CVE-2025-24003","cwe":{"id":"CWE-120","name":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"},"notes":[{"category":"summary","text":"An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.\n\n","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]},"remediations":[{"category":"mitigation","date":"2025-06-03T10:00:00.000Z","details":"This product was designed for use in closed industrial networks. Phoenix Contact strongly recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf). ","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":8.2,"environmentalSeverity":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":8.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]}],"title":"CVE-2025-24003"},{"acknowledgments":[{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"cve":"CVE-2025-24004","cwe":{"id":"CWE-120","name":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"},"notes":[{"category":"summary","text":"A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.\n\n","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]},"remediations":[{"category":"mitigation","date":"2025-06-03T10:00:00.000Z","details":"This product was designed for use in closed industrial networks. Phoenix Contact strongly recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf). ","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"PHYSICAL","availabilityImpact":"LOW","baseScore":5.2,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.2,"environmentalSeverity":"MEDIUM","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.2,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","version":"3.1"},"products":["CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]}],"title":"CVE-2025-24004"},{"acknowledgments":[{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"cve":"CVE-2025-24005","cwe":{"id":"CWE-20","name":"Improper Input Validation"},"notes":[{"category":"summary","text":"A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.","title":"Summary"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"mitigation","date":"2025-06-03T10:00:00.000Z","details":"This product was designed for use in closed industrial networks. Phoenix Contact strongly recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf). ","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware version 1.7.3 which fixes vulnerabilities CVE-2025-24005 and CVE-2025-24006. The vulnerabilities CVE-2025-24002, CVE-2025-24003 and CVE-2025-24004 affect the Eichrecht functionality and in the meantime there is no vendor fix planned for these issues..","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.8,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":7.8,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]}],"title":"CVE-2025-24005"},{"acknowledgments":[{"names":["Jesson Soto Ventura","Matthew Waddell"],"organization":"ivision","summary":"reporting."}],"cve":"CVE-2025-24006","cwe":{"id":"CWE-269","name":"Improper Privilege Management"},"notes":[{"category":"summary","text":"A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.\n","title":"Summary"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"mitigation","date":"2025-06-03T10:00:00.000Z","details":"This product was designed for use in closed industrial networks. Phoenix Contact strongly recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf). ","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware version 1.7.3 which fixes vulnerabilities CVE-2025-24005 and CVE-2025-24006. The vulnerabilities CVE-2025-24002, CVE-2025-24003 and CVE-2025-24004 affect the Eichrecht functionality and in the meantime there is no vendor fix planned for these issues.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.8,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":7.8,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]}],"title":"CVE-2025-24006"}]}