ZDI-CAN-21455: ZDI-24-1047: (0Day) ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-7392.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21455?
The severity of ZDI-CAN-21455 is high as it allows network-adjacent attackers to cause a denial-of-service condition without authentication.
How do I fix ZDI-CAN-21455?
To mitigate ZDI-CAN-21455, ensure that your ChargePoint Home Flex devices are updated to the latest firmware version provided by ChargePoint.
What types of devices are affected by ZDI-CAN-21455?
ZDI-CAN-21455 specifically affects ChargePoint Home Flex charging devices.
Can ZDI-CAN-21455 be exploited remotely?
Yes, ZDI-CAN-21455 can be exploited by network-adjacent attackers without the need for authentication.
What kind of impact does ZDI-CAN-21455 have?
The impact of ZDI-CAN-21455 is a denial-of-service condition, which can render the affected devices inoperable.