PT-2024-8066 · Phoenix Contact · Charx Sec-3100

Chris Anastasio

+1

·

Published

2024-02-02

·

Updated

2025-01-24

·

CVE-2024-25998

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
The OCPP Service is affected by a command injection issue due to improper input validation, allowing an unauthenticated remote attacker to perform command injection with limited privileges. An exploit is available for this issue, with links to the exploit code provided at https://t.co/BZBA0cBOqQ and https://t.co/8lB6fukqj1. The specific software and versions affected are not specified, however, it is mentioned that the issue affects the OCPP Service. #OCPP #commandinjection #infosec #cybersecurityawareness #cybersecurity #hacker #infosecurity

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-09587
CVE-2024-25998
ZDI-24-864

Affected Products

Charx Sec-3100