Products
OCPP Remote service
Source
info@cert.vde.com
Tags
CVE-2024-28136 details
Published : May 14, 2024, 4:16 p.m.
Last Modified : May 14, 2024, 7:18 p.m.
Last Modified : May 14, 2024, 7:18 p.m.
Description
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7.8 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
7.8
Exploitability Score
Impact Score
Base Severity
HIGH
Vector String : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
URL | Source |
---|---|
https://cert.vde.com/en/advisories/VDE-2024-019 | info@cert.vde.com |
This website uses the NVD API, but is not approved or certified by it.