Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23958

Опубликовано: 28 сент. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 8.8
EPSS Низкий

Описание

Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system.

Was ZDI-CAN-23196

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:1.32.00:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_ac_elite_business_c50:-:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23196

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798