ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-507?
The severity of ZDI-26-507 is rated as 46, indicating a significant risk for local privilege escalation.
How do I fix ZDI-26-507?
To fix ZDI-26-507, ensure that you apply the latest security updates provided by Phoenix Contact for the CHARX SEC-3150.
What type of attacks does ZDI-26-507 facilitate?
ZDI-26-507 facilitates local privilege escalation attacks that can be executed by an already authenticated user.
Which devices are affected by ZDI-26-507?
ZDI-26-507 affects installations of Phoenix Contact CHARX SEC-3150 devices.
What prerequisites are needed for exploiting ZDI-26-507?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-26-507.