CVE-2024-7391

ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:chargepoint:home_flex_firmware:5.5.3.13:*:*:*:*:*:*:*
cpe:2.3:h:chargepoint:home_flex:-:*:*:*:*:*:*:*

History

03 Dec 2024, 21:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 2.6
v2 : unknown
v3 : 5.7
First Time Chargepoint
Chargepoint home Flex
Chargepoint home Flex Firmware
CPE cpe:2.3:h:chargepoint:home_flex:-:*:*:*:*:*:*:*
cpe:2.3:o:chargepoint:home_flex_firmware:5.5.3.13:*:*:*:*:*:*:*
References () https://www.zerodayinitiative.com/advisories/ZDI-24-1046/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-1046/ - Third Party Advisory
Summary
  • (es) Vulnerabilidad de divulgación de información de Bluetooth Low Energy en ChargePoint Home Flex. Esta vulnerabilidad permite a los atacantes adyacentes a la red divulgar información confidencial sobre las instalaciones afectadas de los dispositivos de carga ChargePoint Home Flex. Se requiere la interacción del usuario para explotar esta vulnerabilidad. La falla específica existe dentro de la lógica de configuración de Wi-Fi. Al conectarse al dispositivo a través de Bluetooth Low Energy durante el proceso de configuración, un atacante puede obtener credenciales de Wi-Fi. Un atacante puede aprovechar esta vulnerabilidad para divulgar credenciales y obtener acceso a la red Wi-Fi del propietario del dispositivo. Era ZDI-CAN-21454.
CWE NVD-CWE-noinfo

22 Nov 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 22:15

Updated : 2024-12-03 21:44


NVD link : CVE-2024-7391

Mitre link : CVE-2024-7391

CVE.ORG link : CVE-2024-7391


JSON object : View

Products Affected

chargepoint

  • home_flex
  • home_flex_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo