ZDI-24-1047: (0Day) ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-7392.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1047?
The severity of ZDI-24-1047 is critical, as it allows a denial-of-service condition without requiring authentication.
How do I fix ZDI-24-1047?
To fix ZDI-24-1047, update your ChargePoint Home Flex charging device to the latest firmware version provided by the vendor.
Who is affected by ZDI-24-1047?
ZDI-24-1047 affects all installations of ChargePoint Home Flex charging devices.
What type of vulnerability is ZDI-24-1047?
ZDI-24-1047 is a denial-of-service vulnerability that can be exploited by network-adjacent attackers.
Can ZDI-24-1047 be exploited remotely?
Yes, ZDI-24-1047 can be exploited by network-adjacent attackers without the need for authentication.