CVE-2024-28136

A local attacker with low privileges can use a command injection vulnerability to gain root
privileges due to improper input validation using the OCPP Remote service.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
phoenixcontactcharx_sec-3000_firmware
𝑥
≤ 1.5.1
phoenixcontactcharx_sec-3050_firmware
𝑥
≤ 1.5.1
phoenixcontactcharx_sec-3100_firmware
𝑥
≤ 1.5.1
phoenixcontactcharx_sec-3150_firmware
𝑥
≤ 1.5.1
𝑥
= Vulnerable software versions