First published: Thu Aug 01 2024(Updated: )
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software | Affected Version | How to fix |
---|---|---|
ChargePoint Home Flex Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-21455 is high as it allows network-adjacent attackers to cause a denial-of-service condition without authentication.
To mitigate ZDI-CAN-21455, ensure that your ChargePoint Home Flex devices are updated to the latest firmware version provided by ChargePoint.
ZDI-CAN-21455 specifically affects ChargePoint Home Flex charging devices.
Yes, ZDI-CAN-21455 can be exploited by network-adjacent attackers without the need for authentication.
The impact of ZDI-CAN-21455 is a denial-of-service condition, which can render the affected devices inoperable.