PT-2024-22285 · Phoenix Contact · Charx Sec-3100

Sina Kheirkhah

+1

·

Published

2024-05-14

·

Updated

2025-01-24

·

CVE-2024-28135

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Phoenix Contact CHARX SEC-3100 (affected versions not specified)
Description A low privileged remote attacker can exploit a command injection vulnerability in the API, which allows remote code execution as the user-app user due to improper input validation. This issue partly affects confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-28135
ZDI-24-522

Affected Products

Charx Sec-3100