The specific flaw exists within the onboardee module. The issue results from improper access control. An attacker can leverage this vulnerability to execute code in the context of root.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21350 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboardee module. The issue results from improper access control. An attacker can leverage this vulnerability to execute code in the context of root. |
Solution
The vendor states this vulnerability was patched in May 2024.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1048/ |
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 01 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chargepoint
Chargepoint home Flex Hardwired Chargepoint home Flex Hardwired Firmware Chargepoint home Flex Nema 14-50 Plug Chargepoint home Flex Nema 14-50 Plug Firmware Chargepoint home Flex Nema 6-50 Plug Chargepoint home Flex Nema 6-50 Plug Firmware |
|
| CPEs | cpe:2.3:h:chargepoint:home_flex_hardwired:-:*:*:*:*:*:*:* cpe:2.3:h:chargepoint:home_flex_nema_14-50_plug:-:*:*:*:*:*:*:* cpe:2.3:h:chargepoint:home_flex_nema_6-50_plug:-:*:*:*:*:*:*:* cpe:2.3:o:chargepoint:home_flex_hardwired_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:chargepoint:home_flex_nema_14-50_plug_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:chargepoint:home_flex_nema_6-50_plug_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Chargepoint
Chargepoint home Flex Hardwired Chargepoint home Flex Hardwired Firmware Chargepoint home Flex Nema 14-50 Plug Chargepoint home Flex Nema 14-50 Plug Firmware Chargepoint home Flex Nema 6-50 Plug Chargepoint home Flex Nema 6-50 Plug Firmware |
Thu, 13 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Fri, 31 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Fri, 31 Jan 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboardee module. The issue results from improper access control. An attacker can leverage this vulnerability to execute code in the context of root. | |
| Title | ChargePoint Home Flex Improper Access Control | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-01T13:35:46.718Z
Reserved: 2024-01-23T21:45:25.298Z
Link: CVE-2024-23920
Updated: 2025-01-31T16:48:41.873Z
Status : Modified
Published: 2025-01-31T01:15:09.483
Modified: 2025-07-01T14:15:31.183
Link: CVE-2024-23920
No data.
OpenCVE Enrichment
No data.
EUVD