PT-2024-20201 · Autel · Autel Maxicharger Ac Elite Business C50

Published

2024-06-21

·

Updated

2024-10-03

·

CVE-2024-23958

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autel MaxiCharger AC Elite Business C50 (affected versions not specified)
Description This issue allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. The specific flaw exists within the BLE AppAuthenRequest command handler, which uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this to bypass authentication on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-23958
ZDI-24-852

Affected Products

Autel Maxicharger Ac Elite Business C50