CVE-2024-43661 Information
Description
The
This issue affects Iocharger firmware for AC models before version 24120701.
Likelihood: Moderate – An attacker will have to find this exploit by
either obtaining the binaries involved in this vulnerability or by trial
and error. Furthermore the attacker will need a (low privilege)
account to gain access to the
Impact: High – The
CVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N) and there are no additional security measure sin place that need to be circumvented (AC:L) the attack does not rely on preconditions (AT:N). The attack does require authentication but the level of authentication is irrelevant (PR:L) it does not require user interaction (UI:N). The attack leads to reducred availability of the device (VC:N/VI:N/VA:H). THere is not impact on subsequent systems. (SC:N/SI:N/SA:N). Alltough this device is an EV charger handing significant amounts of power we do not forsee a safety impact. The attack can be automated (AU:Y). Because the DoS condition is written to disk persistantly it cannot be recovered by the user (R:I).
Reference
https://csirt.divd.nl/CVE-2024-43661/ https://csirt.divd.nl/DIVD-2024-00035/ https://iocharger.com
Share on: