CVE-2024-25994: PHOENIX CONTACT: Unintended script file upload in CHARX Series
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25994?
CVE-2024-25994 is considered a high severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2024-25994?
To mitigate CVE-2024-25994, you should upgrade the firmware of the affected Phoenix Contact CHARX devices to version 1.5.1 or later.
Which devices are affected by CVE-2024-25994?
CVE-2024-25994 affects the Phoenix Contact CHARX series devices, specifically the CHARX SEC-3000, 3050, 3100, and 3150 firmware versions prior to 1.5.1.
What attack vector does CVE-2024-25994 exploit?
CVE-2024-25994 exploits improper input validation that allows unauthenticated remote attackers to upload arbitrary script files.
What are the consequences of exploiting CVE-2024-25994?
Exploitation of CVE-2024-25994 can lead to the execution of arbitrary scripts on the affected devices, potentially compromising their functionality and security.