CVE-2024-5684
Last modified
CVE-2024-5684 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Vw | Id.Charger Connect Firmware | spr3.2 | Beta |
| Vw | Id.Charger Connect Firmware | spr3.51 | — |
| Vw | Id.Charger Connect Firmware | spr3.52 | — |
| Vw | Id.Charger Pro Firmware | spr3.2 | Beta |
| Vw | Id.Charger Pro Firmware | spr3.51 | — |
| Vw | Id.Charger Pro Firmware | spr3.52 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5684?
How severe is CVE-2024-5684?
How do I fix CVE-2024-5684?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56830The Net::EasyTCP package 0.15 through 0.26 for Perl uses Per…5.4
- CVE-2024-56835A vulnerability has been identified in RUGGEDCOM ROX MX5000 …8.8
- CVE-2024-56836A vulnerability has been identified in RUGGEDCOM ROX MX5000 …8.8
- CVE-2024-56837A vulnerability has been identified in RUGGEDCOM ROX MX5000 …8.6
- CVE-2024-56838A vulnerability has been identified in RUGGEDCOM ROX MX5000 …8.6
- CVE-2024-56839A vulnerability has been identified in RUGGEDCOM ROX MX5000 …8.6
- CVE-2024-56840A vulnerability has been identified in RUGGEDCOM ROX MX5000 …7.5
- CVE-2024-56841A vulnerability has been identified in Mendix LDAP (All vers…9.1
- CVE-2024-5685Users with "User:edit" and "Self:api" permissions can promot…8.1
- CVE-2024-5686The WPZOOM Addons for Elementor (Templates, Widgets) plugin …5.4
- CVE-2024-5687If a specific sequence of actions is performed when opening …5.3
- CVE-2024-5688If a garbage collection was triggered at the right time, a u…8.1
Are you affected by CVE-2024-5684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
