7.8

CVE-2024-28133

PHOENIX CONTACT: Privilege escalation in CHARX Series

	
		
		
	
	
		
			
				
					A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root
privileges. 



				


			


		


	



				


			


		


	
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Charx Sec-3000 Firmware Version <= 1.5.1
   Phoenixcontact ≫ Charx Sec-3000 Version -
Phoenixcontact ≫ Charx Sec-3050 Firmware Version <= 1.5.1
   Phoenixcontact ≫ Charx Sec-3050 Version -
Phoenixcontact ≫ Charx Sec-3100 Firmware Version <= 1.5.1
   Phoenixcontact ≫ Charx Sec-3100 Version -
Phoenixcontact ≫ Charx Sec-3150 Firmware Version <= 1.5.1
   Phoenixcontact ≫ Charx Sec-3150 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.296
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

https://cert.vde.com/en/advisories/VDE-2024-019
Third Party Advisory