Description
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Published: 2026-07-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the init‑script invoked by the user‑applications start routine allows a low‑privileged local user to execute arbitrary commands with root privileges, thereby fully compromising the system. This is a command injection weakness (CWE‑78) that directly enables unauthorized modification of configuration, data, or services.

Affected Systems

The vulnerability affects Phoenix Contact CHARX SEC‑3000, SEC‑3050, SEC‑3100, and SEC‑3150 devices. No firmware build numbers are specified, so any firmware on those model lines that contains the unpatched init‑script is potentially impacted.

Risk and Exploitability

The CVSS score of 8.5 classifies the flaw as high severity. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation, and it is not listed in CISA’s KEV catalog. Exploitation requires local access; a non‑privileged user can manipulate the init‑script or invoke its start routine to trigger the privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 11:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Phoenix Contact that patches the vulnerable init‑script for user‑applications.
  • If an immediate firmware upgrade is not feasible, disable the vulnerable init‑script by renaming /etc/init.d/user-applications or removing its execute permission, then restart the device to ensure it no longer auto‑starts.
  • Continuously monitor system logs for attempts to execute /etc/init.d/user-applications or any unauthorized root access, and enforce strict physical access controls to mitigate local attack potential.
  • Check the vendor’s website or support portal for additional updates or advisory notes that may refine the remediation steps.

Generated by OpenCVE AI on August 3, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Title Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-78
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T12:55:41.446Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:57.260

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-44093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')