PT-2024-20201 · Autel · Autel Maxicharger Ac Elite Business C50

CVE-2024-23958

·

Published

2024-06-21

·

Updated

2024-10-03

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autel MaxiCharger AC Elite Business C50 (affected versions not specified)
Description This issue allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. The specific flaw exists within the BLE AppAuthenRequest command handler, which uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this to bypass authentication on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23958
ZDI-24-852

Affected Products

Autel Maxicharger Ac Elite Business C50