CVE-2024-28133: PHOENIX CONTACT: Privilege escalation in CHARX Series
Published May 14, 2024
·Updated
A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges.
Affected Software
9 affected components
Phoenix Contact CHARX Series
All of the following
Phoenixcontact Charx Sec-3000 Firmware<=1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<=1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<=1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<=1.5.1
Phoenixcontact Charx Sec-3150
Event History
May 14, 2024
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28133?
CVE-2024-28133 is categorized as a low severity vulnerability.
2
How does CVE-2024-28133 affect the CHARX systems?
CVE-2024-28133 allows a local low privileged attacker to exploit an untrusted search path in CHARX utilities to gain root privileges.
3
What versions of the CHARX firmware are affected by CVE-2024-28133?
CVE-2024-28133 affects versions up to and including 1.5.1 of the Phoenix Contact CHARX firmware.
4
Can CVE-2024-28133 be exploited remotely?
No, CVE-2024-28133 requires local access to the CHARX system to be exploited.
5
What steps should I take to mitigate CVE-2024-28133?
To mitigate CVE-2024-28133, upgrade to the latest firmware version that addresses this vulnerability.