Skip to main content
CVE Vulnerability Database

CVE-2024-3913: Phoenix Contact Charx SEC-3150 Auth Bypass

CVE-2024-3913 is an authentication bypass flaw in Phoenix Contact Charx SEC-3150 Firmware that lets unauthenticated attackers modify device configuration during startup. This article covers technical details, impact, and mitigation.

Published:

CVE-2024-3913 Overview

CVE-2024-3913 affects Phoenix Contact CHARX SEC electric vehicle charging controllers. An unauthenticated remote attacker on the adjacent network can modify device configuration by writing to a file that remains writable for a short period after system startup. The flaw is tracked as CWE-552: Files or Directories Accessible to External Parties.

The vulnerability affects the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 charging controllers used in EV charging infrastructure. Successful exploitation allows configuration tampering without authentication, impacting device integrity.

Critical Impact

An unauthenticated adjacent-network attacker who wins the startup race window can alter device configuration on affected CHARX SEC charging controllers, undermining the integrity of EV charging operations.

Affected Products

  • Phoenix Contact CHARX SEC-3000 and CHARX SEC-3000 firmware
  • Phoenix Contact CHARX SEC-3050 and CHARX SEC-3050 firmware
  • Phoenix Contact CHARX SEC-3100 and CHARX SEC-3100 firmware
  • Phoenix Contact CHARX SEC-3150 and CHARX SEC-3150 firmware

Discovery Timeline

  • 2024-08-13 - CVE-2024-3913 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-3913

Vulnerability Analysis

The vulnerability is a file exposure and race condition issue in the CHARX SEC firmware boot process. During system startup, a configuration-relevant file becomes writable for a short interval before permissions are hardened. An attacker who reaches the device on the local or adjacent network during this window can write attacker-controlled content to that file.

Because no authentication check gates the write, the attacker does not require credentials, keys, or a prior foothold on the controller. Exploitation modifies device behavior by tampering with configuration state. The impact centers on integrity: charging policy, network settings, or operational parameters can be altered by an external party.

Exploitation requires the attacker to be present on the adjacent network and to time the write against the startup window, which raises attack complexity but does not eliminate risk in shared or exposed operational technology (OT) environments.

Root Cause

The root cause is improper file permission enforcement during the startup sequence, categorized under CWE-552. A configuration file is created or left in a writable state before access controls are applied, exposing it to external parties on the network path.

Attack Vector

The attack vector is the adjacent network. An unauthenticated remote attacker with network reachability to the CHARX SEC controller during boot connects to the exposed file interface and writes modified configuration content before permission tightening completes. No user interaction is required. Refer to VDE Security Advisory VDE-2024-022 for vendor-provided technical details.

Detection Methods for CVE-2024-3913

Indicators of Compromise

  • Unexpected configuration changes on CHARX SEC-3000, 3050, 3100, or 3150 controllers following a reboot or power cycle
  • Network connections to the controller from unauthorized hosts on the adjacent segment during device startup
  • Divergence between the running device configuration and the last known-good configuration backup

Detection Strategies

  • Baseline the expected configuration of each CHARX SEC controller and compare against the running configuration on a scheduled cadence
  • Monitor management-plane and file-service traffic to charging controllers, alerting on writes originating outside the operations network
  • Correlate device reboot events with subsequent inbound network activity within the startup window

Monitoring Recommendations

  • Forward controller logs and network flow telemetry from the OT segment to a centralized SIEM or data lake for retention and correlation
  • Alert on repeated reboot patterns of CHARX SEC controllers, which may indicate an attacker forcing the writable-file window to reopen
  • Track firmware version inventory for the CHARX SEC-3000, 3050, 3100, and 3150 product lines to confirm patched status

How to Mitigate CVE-2024-3913

Immediate Actions Required

  • Apply the firmware update referenced in VDE Security Advisory VDE-2024-022 to all affected CHARX SEC controllers
  • Restrict network reachability to CHARX SEC management interfaces to trusted operations hosts only
  • Verify that CHARX SEC devices are not exposed to untrusted or public networks, including guest Wi-Fi or shared parking-facility segments

Patch Information

Phoenix Contact and VDE CERT have published remediation guidance in VDE Security Advisory VDE-2024-022. Operators of CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 controllers should consult the advisory for the fixed firmware versions and upgrade instructions.

Workarounds

  • Place CHARX SEC controllers behind a dedicated firewall or VLAN that restricts inbound traffic to authorized management stations
  • Disable or block unused network services on the controller to reduce reachable attack surface during startup
  • Physically secure charging station cabinets to limit unauthorized adjacent-network access via exposed Ethernet ports

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.