CVE-2024-23971
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 31, 2025
CWE ID 77
Summary
CVE-2024-23971 is a critical vulnerability affecting ChargePoint Home Flex charging stations. It enables network-adjacent attackers to execute arbitrary code on vulnerable installations without requiring authentication. The underlying cause is the improper handling of OCPP messages in the software. An attacker can exploit this issue by providing malicious user-supplied strings that are not adequately validated before being used in system calls, resulting in the execution of unintended code in root context.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.