CVE-2024-23971
CVE-2024-23971 allows network-adjacent attackers to execute arbitrary code on ChargePoint Home Flex charging stations. This vulnerability exists because of improper validation of OCPP messages, leading to a system call execution with a user-supplied string. An attacker can execute code with root privileges without authentication. The SVRS score of 30 indicates a moderate risk; although not critical, proactive monitoring is still recommended. Exploitation of this vulnerability can result in complete compromise of the charging station, potentially leading to unauthorized access and control. Immediate patching is not essential, but staying informed and monitoring for exploitation attempts is prudent.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.