ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability.
The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-24-1046/ |
History
Tue, 03 Dec 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Chargepoint
Chargepoint home Flex Chargepoint home Flex Firmware |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:h:chargepoint:home_flex:-:*:*:*:*:*:*:* cpe:2.3:o:chargepoint:home_flex_firmware:5.5.3.13:*:*:*:*:*:*:* |
|
Vendors & Products |
Chargepoint
Chargepoint home Flex Chargepoint home Flex Firmware |
|
Metrics |
cvssV3_1
|
Tue, 26 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 22 Nov 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454. | |
Title | ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: zdi
Published: 2024-11-22T21:31:18.047Z
Updated: 2024-11-26T15:59:17.260Z
Reserved: 2024-08-01T20:11:51.555Z
Link: CVE-2024-7391
Vulnrichment
Updated: 2024-11-26T15:59:13.782Z
NVD
Status : Analyzed
Published: 2024-11-22T22:15:17.893
Modified: 2024-12-03T21:44:10.397
Link: CVE-2024-7391
Redhat
No data.