Status: UPDATED
| Advisory ID: CVE-2026-44108
Key Details
| CVE | CVE-2026-44108 |
| CVSS Score / Version | 9.8 (Critical) / CVSS v3.1 |
| Updated | 2026-07-30 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100, Phoenix Contact CHARX SEC-3050, and Phoenix Contact CHARX SEC-3000 |
| Classified as | CWE-696 (Incorrect Behavior Order) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. (NVD)
What to Do
Monitor Phoenix Contact's web page for any future patch releases.
References