PT-2024-20209 · Chargepoint · Chargepoint Home Flex

Daan Keuper

+2

·

Published

2024-08-01

·

Updated

2025-09-30

·

CVE-2024-23970

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ChargePoint Home Flex (affected versions not specified)
Description This issue allows network-adjacent attackers to compromise transport security on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the CURLOPT SSL VERIFYHOST setting, resulting from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other issues to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-23970
ZDI-24-1052

Affected Products

Chargepoint Home Flex