Status: UPDATED
| Advisory ID: CVE-2026-41032
Key Details
| CVE | CVE-2026-41032 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100, Phoenix Contact CHARX SEC-3050, and Phoenix Contact CHARX SEC-3000 |
| Classified as | CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
What to Do
Monitor Phoenix Contact's web page for any future patch releases.
References