CVE Feed

    Dashboard / CVE / CVE-2024-11666

    CVE-2024-11666

    Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated users  suitably positioned on the network between an EV charger controller and eCharge infrastructure can execute arbitrary commands with elevated privileges on affected devices. This issue affects cph2_echarge_firmware: through 2.0.4.

    Published:Nov 24, 2024
    Last Modified:Dec 3, 2024
    EPS:Nov 24, 2024
    EPSS Score:0.00333
    CVSS Score:9

    Affected Products

    Vendor
    Echarge
    Product
    Salia Plcc
    Vendor
    Echarge
    Product
    Salia Plcc Firmware
    Vendor
    Hardy-barth
    Product
    Cph2 Echarge Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High