Back to Database
Status published
High
CVE-2024-25999
PHOENIX CONTACT: Privilege escalation in the OCPP agent service
Vulnerability Description
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25999
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chris Anastasio
- Fabius Watson
More from PHOENIX CONTACT
View All →CVE-2025-41668
Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile
High
8.8
CVE-2025-41667
Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script
High
8.8
CVE-2025-41666
Phoenix Contact: File access due to the replacement of a critical file used by the watchdog
High
8.8
CVE-2025-41665
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible
Medium
6.5
CVE-2024-7734
Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
Medium
5.3
Affected Vendor
PHOENIX CONTACT
View all reports →Affected Software
CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, CHARX SEC-3150
Vulnerable Versions:
0
Timeline
Official Publish:
March 12th, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H