Phoenix Contact CHARX SEC-3000
cpe:2.3:h:phoenixcontact:charx_sec-3000:*:*:*:*:*:*:*, +1 more
- < 1.7.0
A vulnerability in Phoenix Contact CHARX SEC-3000 series charge controllers, all versions prior to 1.7.0, allows an authenticated low-privileged user to escalate privileges and gain root access. This issue arises from improper file permission handling, which can be exploited to alter access rights and elevate user privileges.
Exploitation of this vulnerability allows the authenticated user 'user-app' to gain root rights, leading to unauthorized access and control over the device.
Users are strongly advised to upgrade to firmware version 1.7.0 or higher, which addresses this vulnerability. For additional guidance on protecting network-capable devices, consult the General Recommendation from Phoenix Contact.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.