Vulnerability Description
ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chargepoint | Home Flex Firmware | 5.5.3.13 |
| Chargepoint | Home Flex | - |
Related Weaknesses (CWE)
References
- https://www.zerodayinitiative.com/advisories/ZDI-24-1046/Third Party Advisory
FAQ
What is CVE-2024-7391?
CVE-2024-7391 is a vulnerability with a CVSS score of 5.7 (MEDIUM). ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Cha...
How severe is CVE-2024-7391?
CVE-2024-7391 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7391?
Check the references section above for vendor advisories and patch information. Affected products include: Chargepoint Home Flex Firmware, Chargepoint Home Flex.