CVE-2024-25999: PHOENIX CONTACT: Privilege escalation in the OCPP agent service
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25999?
CVE-2024-25999 is classified with a high severity due to potential privilege escalation by an unauthenticated local attacker.
How do I fix CVE-2024-25999?
To fix CVE-2024-25999, ensure that the affected Phoenix Contact Charx Sec firmware is updated to versions greater than 1.5.1.
Who is affected by CVE-2024-25999?
CVE-2024-25999 affects users of Phoenix Contact Charx Sec-3000, Charx Sec-3050, Charx Sec-3100, and Charx Sec-3150 firmware versions earlier than 1.5.1.
What type of attack does CVE-2024-25999 enable?
CVE-2024-25999 enables a privilege escalation attack through improper input validation in the OCPP agent service.
Can CVE-2024-25999 be exploited remotely?
No, CVE-2024-25999 can only be exploited by a local attacker as it requires physical access to the affected systems.