CVE-2026-44092
8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 | 1.0.0 < 1.9.1 | affected |
| Phoenix Contact | CHARX SEC-3100 | 1.0.0 < 1.9.1 | affected |
| Phoenix Contact | CHARX SEC-3050 | 1.0.0 < 1.9.1 | affected |
| Phoenix Contact | CHARX SEC-3000 | 1.0.0 < 1.9.1 | affected |
Weaknesses
- CWE-93: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.