PHOENIX CONTACT: command injection vulnerability in the API of the CHARX Series
Vulnerability Description
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28135
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Trend Micro's Zero Day Initiative
- Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)
More from PHOENIX CONTACT
View All →Affected Vendor
PHOENIX CONTACT
View all reports →