CVE-2024-7392
MEDIUMDescription
ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-21455.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| chargepoint | home_flex_firmware |
| chargepoint | home_flex |
References
Other References
Frequently Asked Questions
What is CVE-2024-7392? +
How severe is CVE-2024-7392? +
What products are affected by CVE-2024-7392? +
How do I check if I'm vulnerable to CVE-2024-7392? +
Related Vulnerabilities
When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of …
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large …
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted …
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable …
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management …