CVE-2024-26005: PHOENIX CONTACT: Privilege gain through incomplete cleanup in CHARX Series
An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26005?
CVE-2024-26005 is categorized as a high-severity vulnerability due to its potential for unauthorized privilege escalation.
How do I fix CVE-2024-26005?
To fix CVE-2024-26005, upgrade the affected Phoenix Contact CHARX devices to firmware version 1.5.1 or later.
Who is affected by CVE-2024-26005?
CVE-2024-26005 affects users of Phoenix Contact CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 firmware versions prior to 1.5.1.
What type of attack does CVE-2024-26005 involve?
CVE-2024-26005 involves an unauthenticated remote attacker exploiting incomplete cleanup during service restarts after a denial-of-service (DoS) attack.
What are the potential impacts of CVE-2024-26005?
The potential impacts of CVE-2024-26005 include unauthorized service level privileges, which could facilitate further attacks or unauthorized access.