Phoenix Contact CHARX SEC-3000
cpe:2.3:h:phoenixcontact:charx_sec-3000:*:*:*:*:*:*:*, +1 more
- <= 1.6.5
- < 1.7.3
A privilege escalation vulnerability has been identified in Phoenix Contact CHARX SEC-3xxx charging controllers, specifically in versions through 1.6.5 and in the 1.7.2 version range. This vulnerability allows a local attacker with a user account to escalate privileges to root by exploiting a vulnerable script via SSH, due to improper input validation.
Exploitation of this vulnerability can lead to unauthorized privilege escalation, allowing a local user to gain root access on the affected device.
Users are advised to upgrade to firmware version 1.7.3, which addresses this vulnerability. For general security recommendations, refer to the Phoenix Contact Application Note Security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.