CVE-2024-26002: PHOENIX CONTACT: File ownership manipulation in CHARX Series
Published Mar 12, 2024
·Updated
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
Affected Software
8 affected components
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.5.1
Phoenixcontact Charx Sec-3150
Event History
Mar 12, 2024
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-26002?
CVE-2024-26002 is considered to be of medium severity due to improper input validation leading to potential root access.
2
How do I fix CVE-2024-26002?
To fix CVE-2024-26002, update the firmware of the affected Phoenix Contact CHARX SEC devices to version higher than 1.5.1.
3
Which devices are affected by CVE-2024-26002?
CVE-2024-26002 affects the firmware versions up to 1.5.1 of Phoenix Contact CHARX SEC-3000, 3050, 3100, and 3150.
4
What type of attack does CVE-2024-26002 facilitate?
CVE-2024-26002 enables a local attacker with low privileges to gain root access by manipulating file ownership.
5
Is exploitation of CVE-2024-26002 easy for an attacker?
Yes, exploitation of CVE-2024-26002 is straightforward for a local attacker due to the improper input validation.