System logs could be accessed through web management application due to a lack of access control.
An attacker can obtain the following sensitive information:
• Wi-Fi access point credentials to which the EV charger can connect.
• APN web address and credentials.
• IPSEC credentials.
• Web interface access credentials for user and admin accounts.
• JuiceBox system components (software installed, model, firmware version, etc.).
• C2G configuration details.
• Internal IP addresses.
• OTA firmware update configurations (DNS servers).
All the credentials are stored in logs in an unencrypted plaintext format.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: • Wi-Fi access point credentials to which the EV charger can connect. • APN web address and credentials. • IPSEC credentials. • Web interface access credentials for user and admin accounts. • JuiceBox system components (software installed, model, firmware version, etc.). • C2G configuration details. • Internal IP addresses. • OTA firmware update configurations (DNS servers). All the credentials are stored in logs in an unencrypted plaintext format. | |
Title | Unauthorized System Log Disclosure in Enel X JuiceBox | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ASRG
Published: 2024-11-05T15:01:08.666Z
Updated: 2024-11-05T17:00:26.636Z
Reserved: 2023-03-31T10:22:52.667Z
Link: CVE-2023-29114
Vulnrichment
Updated: 2024-11-05T17:00:21.957Z
NVD
Status : Awaiting Analysis
Published: 2024-11-05T15:15:21.443
Modified: 2024-11-05T17:15:05.277
Link: CVE-2023-29114
Redhat
No data.