CVE-2024-28137: PHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series
Published May 14, 2024
·Updated
A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.
Affected Software
9 affected components
Phoenix Contact CHARX Series
All of the following
Phoenixcontact Charx Sec-3000 Firmware<=1.5.1
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<=1.5.1
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<=1.5.1
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<=1.5.1
Phoenixcontact Charx Sec-3150
Event History
May 14, 2024
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28137?
CVE-2024-28137 has a critical severity due to its potential for privilege escalation by local attackers.
2
How do I fix CVE-2024-28137?
To fix CVE-2024-28137, update your Phoenix Contact CHARX firmware to a version greater than 1.5.1.
3
Which Phoenix Contact products are affected by CVE-2024-28137?
CVE-2024-28137 affects Phoenix Contact CHARX Sec-3000, Sec-3050, Sec-3100, and Sec-3150 firmware versions up to and including 1.5.1.
4
What type of vulnerability is CVE-2024-28137?
CVE-2024-28137 is a TOCTOU (Time of Check to Time of Use) vulnerability allowing privilege escalation.
5
Can an attacker exploit CVE-2024-28137 remotely?
No, CVE-2024-28137 requires local access for exploitation.