漏洞标题
ChargePoint Home Flex 不正证书验证漏洞
漏洞描述信息
此漏洞允许网络相邻的攻击者破坏ChargePoint Home Flex充电桩的传输安全。利用此漏洞无需进行身份验证。
具体缺陷存在于CURLOPT_SSL_VERIFYHOST设置中。问题源于服务器提供的证书验证不当。攻击者可以利用此漏洞结合其他漏洞以root身份执行代码。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
证书验证不恰当
漏洞标题
ChargePoint Home Flex Improper Certificate Validation
漏洞描述信息
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
CVSS信息
N/A
漏洞类别
N/A