CVE-2026-44097
Deferred Deferred - Pending Action

Operator File Upload Allows DoS in Industrial Control System

Vulnerability report for CVE-2026-44097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: CERT VDE

Description

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
phoenix_contact charx_sec-3xxx to 1.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A low-privileged remote attacker with operator access can upload arbitrary files via a REST endpoint meant for firmware updates. This allows storing attacker-controlled files persistently and may exhaust system resources, potentially causing Denial-of-Service.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized firmware update requests or file uploads to the REST endpoint. Check for unexpected files in firmware storage directories and resource exhaustion on the device. Inspect logs for repeated failed authentication attempts or unusual MQTT broker access patterns.

Impact Analysis

An attacker could upload malicious files to the device, leading to persistent compromise. This might cause system crashes due to resource exhaustion, disrupting operations and potentially enabling further attacks.

Compliance Impact

The vulnerability allows low-privileged attackers to upload arbitrary files, potentially leading to resource exhaustion and Denial-of-Service. This could disrupt operations handling sensitive data, impacting compliance with GDPR or HIPAA by compromising availability or integrity of personal health or user data.

Mitigation Strategies

Update firmware to the latest version immediately to prevent unauthorized file uploads and resource exhaustion. Restrict operator access to only necessary functions and monitor network traffic for unusual file uploads to the firmware update endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart