CVE-2024-28137
PHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.
Un atacante local con privilegios bajos puede realizar una escalada de privilegios con un script de inicio debido a una vulnerabilidad de TOCTOU.
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3100 charging controllers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the /etc/init.d/user-applications script. By creating a symbolic link, an attacker can abuse the script to change ownership of arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-05 CVE Reserved
- 2024-05-14 CVE Published
- 2024-06-01 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2024-019 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
PHOENIX CONTACT Search vendor "PHOENIX CONTACT" | CHARX SEC-3000 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3000" | <= 1.5.1 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3000" and version " <= 1.5.1" | en |
Affected
| ||||||
PHOENIX CONTACT Search vendor "PHOENIX CONTACT" | CHARX SEC-3050 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3050" | <= 1.5.1 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3050" and version " <= 1.5.1" | en |
Affected
| ||||||
PHOENIX CONTACT Search vendor "PHOENIX CONTACT" | CHARX SEC-3100 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3100" | <= 1.5.1 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3100" and version " <= 1.5.1" | en |
Affected
| ||||||
PHOENIX CONTACT Search vendor "PHOENIX CONTACT" | CHARX SEC-3150 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3150" | <= 1.5.1 Search vendor "PHOENIX CONTACT" for product "CHARX SEC-3150" and version " <= 1.5.1" | en |
Affected
|