PT-2024-17176 · Unknown · Cph2 Echarge Firmware
Quentin Kaiser
·
Published
2024-11-24
·
Updated
2024-12-03
·
CVE-2024-11666
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cph2 echarge firmware versions through 2.0.4
Description
The issue affects devices that communicate with the eCharge cloud infrastructure over an insecure channel, as peer verification is disabled. This allows remote unauthenticated users, suitably positioned on the network between an EV charger controller and eCharge infrastructure, to execute arbitrary commands with elevated privileges on affected devices.
Recommendations
For cph2 echarge firmware versions through 2.0.4, update to a version that addresses the peer verification issue to prevent remote attacks.
As a temporary workaround, consider restricting network access to the eCharge cloud infrastructure to minimize the risk of exploitation.
Restrict access to the affected devices to prevent remote unauthenticated users from executing arbitrary commands with elevated privileges.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cph2 Echarge Firmware