CVE-2025-24006 describes a privilege escalation vulnerability affecting Phoenix Contact CHARX SEC-3000 and SEC-3050 series devices. A low-privileged local attacker can exploit insecure SSH permissions to gain root access. This vulnerability carries a CVSS score of 7.8 (HIGH), indicating a significant risk with local access, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.3CPE matchmatch criteria | cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:* | ||
< 1.7.3CPE matchmatch criteria | cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:* | ||
< 1.7.3CPE matchmatch criteria | cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:* | ||
< 1.7.3CPE matchmatch criteria | cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.