CVE-2024-25998: PHOENIX CONTACT: Command injection in the OCPP Service
Published Mar 12, 2024
·Updated
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
Affected Software
9 affected components
Phoenix Contact OCPP Service
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.5.1
Phoenixcontact Charx Sec-3150
Event History
Mar 12, 2024
CVE Published
via MITRE·08:11 AM
Data Sourced
via MITRE·08:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25998?
CVE-2024-25998 is classified as a critical vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2024-25998?
To mitigate CVE-2024-25998, ensure proper input validation in the OCPP Service and update to the latest firmware version.
3
What systems are affected by CVE-2024-25998?
CVE-2024-25998 affects Phoenix Contact OCPP Service versions prior to specified firmware updates.
4
Who can exploit CVE-2024-25998?
An unauthenticated remote attacker can exploit CVE-2024-25998 due to improper input validation.
5
What type of vulnerability is CVE-2024-25998?
CVE-2024-25998 is a command injection vulnerability that allows attackers to execute arbitrary commands.