CVE-2024-5684
MEDIUMDescription
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.
Is your site exposed to CVE-2024-5684?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| vw | id.charger_connect_firmware |
| vw | id.charger_connect_firmware |
| vw | id.charger_connect_firmware |
| vw | id.charger_connect |
| vw | id.charger_pro_firmware |
| vw | id.charger_pro_firmware |
| vw | id.charger_pro_firmware |
| vw | id.charger_pro |
References
Other References
Frequently Asked Questions
What is CVE-2024-5684? +
How severe is CVE-2024-5684? +
What products are affected by CVE-2024-5684? +
How do I check if I'm vulnerable to CVE-2024-5684? +
Related Vulnerabilities
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed …
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, …
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated …
stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege …
Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior …
RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in …