PT-2024-10857 · Circontrol · Circontrol Raption

Abert Spruyt

+2

·

Published

2024-11-07

·

Updated

2024-11-13

·

CVE-2020-8007

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Circontrol Raption versions through 5.6.2
Description The pwrstudio web application of EV Charger is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip. This issue affects Circontrol's Raption 150 DC chargers. To mitigate risks, ensure your systems are updated to the latest version.
Recommendations For versions through 5.6.2, update to the latest version to mitigate risks. As a temporary workaround, consider restricting access to the configuration menu fields ntpserver0, ntpserver1, and pingip until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-8007

Affected Products

Circontrol Raption