ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability.
The specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1046/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    03 Dec 2024, 21:44
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.7 | 
| First Time | Chargepoint home Flex Firmware Chargepoint home Flex Chargepoint | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-24-1046/ - Third Party Advisory | |
| CPE | cpe:2.3:o:chargepoint:home_flex_firmware:5.5.3.13:*:*:*:*:*:*:* cpe:2.3:h:chargepoint:home_flex:-:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| Summary | 
 | 
22 Nov 2024, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-22 22:15
Updated : 2024-12-03 21:44
NVD link : CVE-2024-7391
Mitre link : CVE-2024-7391
CVE.ORG link : CVE-2024-7391
JSON object : View
Products Affected
                chargepoint
- home_flex
- home_flex_firmware
CWE
                