Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5684

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 6.3
CVSS3: 8.8
EPSS Низкий

Описание

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:vw:id.charger_connect_firmware:spr3.2:beta:*:*:*:*:*:*
cpe:2.3:o:vw:id.charger_connect_firmware:spr3.51:*:*:*:*:*:*:*
cpe:2.3:o:vw:id.charger_connect_firmware:spr3.52:*:*:*:*:*:*:*
cpe:2.3:h:vw:id.charger_connect:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

Одно из

cpe:2.3:o:vw:id.charger_pro_firmware:spr3.2:beta:*:*:*:*:*:*
cpe:2.3:o:vw:id.charger_pro_firmware:spr3.51:*:*:*:*:*:*:*
cpe:2.3:o:vw:id.charger_pro_firmware:spr3.52:*:*:*:*:*:*:*
cpe:2.3:h:vw:id.charger_pro:-:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.00023
Низкий

6.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-345
CWE-345

Связанные уязвимости

CVSS3: 6.3
github
больше 1 года назад

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.

EPSS

Процентиль: 6%
0.00023
Низкий

6.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-345
CWE-345