First published: Thu Aug 01 2024(Updated: )
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software | Affected Version | How to fix |
---|---|---|
ChargePoint Home Flex Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-24-1047 is critical, as it allows a denial-of-service condition without requiring authentication.
To fix ZDI-24-1047, update your ChargePoint Home Flex charging device to the latest firmware version provided by the vendor.
ZDI-24-1047 affects all installations of ChargePoint Home Flex charging devices.
ZDI-24-1047 is a denial-of-service vulnerability that can be exploited by network-adjacent attackers.
Yes, ZDI-24-1047 can be exploited by network-adjacent attackers without the need for authentication.