CVE-2024-25996: PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series
Published Mar 12, 2024
·Updated
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
Affected Software
9 affected components
Phoenix Contact CHARX Series
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.5.1
Phoenixcontact Charx Sec-3150
Event History
Mar 12, 2024
CVE Published
via MITRE·08:11 AM
Data Sourced
via MITRE·08:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25996?
CVE-2024-25996 has a high severity rating due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2024-25996?
To fix CVE-2024-25996, you should update the affected Phoenix Contact CHARX firmware to version 1.5.1 or later.
3
What products are affected by CVE-2024-25996?
CVE-2024-25996 affects Phoenix Contact CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 firmware versions below 1.5.1.
4
Can CVE-2024-25996 be exploited remotely?
Yes, an unauthenticated remote attacker can exploit CVE-2024-25996 to execute code on the affected devices.
5
Is authentication required to exploit CVE-2024-25996?
No, CVE-2024-25996 can be exploited without authentication, making it especially critical.