CVE-2024-28136: PHOENIX CONTACT: command injection gains root privileges using the OCPP remote service
Published May 14, 2024
·Updated
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
Affected Software
8 affected components
All of the following
Phoenixcontact Charx Sec-3000 Firmware<=1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<=1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<=1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<=1.5.1
Phoenixcontact Charx Sec-3150
Event History
May 14, 2024
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28136?
CVE-2024-28136 is classified as a critical vulnerability due to the potential for local attackers to escalate privileges to root.
2
How do I fix CVE-2024-28136?
To mitigate CVE-2024-28136, update the affected Phoenix Contact CHARX SEC firmware to version 1.5.2 or later.
3
Which products are affected by CVE-2024-28136?
CVE-2024-28136 affects Phoenixcontact CHARX SEC-3000, 3050, 3100, and 3150 firmware versions up to 1.5.1.
4
What types of attacks can exploit CVE-2024-28136?
CVE-2024-28136 can be exploited through command injection by local attackers with low privileges.
5
What is the impact of CVE-2024-28136 on my system?
The impact of CVE-2024-28136 allows an attacker to gain root privileges, compromising the entire system security.