目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2024-43648— iocharger 安全漏洞

AI 预测 8.8 利用难度: 中等 EPSS 2.70% · P86
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-43648 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Authenticated command injection via <redacted>.exe <redacted> parameter
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Iocharger firmware for AC models before version 24120701. Likelihood: Moderate – This action is not a common place for command injection vulnerabilities to occur. Thus, an attacker will likely only be able to find this vulnerability by reverse-engineering the firmware or trying it on all <redacted> fields. The attacker will also need a (low privilege) account to gain access to the <redacted> binary, or convince a user with such access to execute a payload. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete files and services. CVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N), and there are no additional security measure sin place that need to be circumvented (AC:L), the attack does not rely on preconditions (AT:N). The attack does require authentication, but the level of authentication is irrelevant (PR:L), it does not require user interaction (UI:N). If is a full system compromise, potentially fully compromising confidentiality, integrity and availability of the devicer (VC:H/VI:H/VA:H).  A compromised charger can be used to "pivot" onto networks that should otherwise be closed, cause a low confidentiality and interity impact on subsequent systems. (SC:L/SI:L/SA:H). Because this device is an EV charger handing significant amounts of power, we suspect this vulnerability can have a safety impact (S:P). The attack can be automated (AU:Y).
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
iocharger 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
iocharger是中国银河樟坛(iocharger)公司的一个电动汽车充电和智能能源管理解决方案。 iocharger 24120701之前版本存在安全漏洞,该漏洞源于存在命令注入,会导致以root用户身份执行远程代码。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
IochargerIocharger firmware for AC models 0 ~ 24120701 -

二、漏洞 CVE-2024-43648 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-43648 的情报信息

登录查看更多情报信息。

CVE-2024-43648 厂商安全公告 (2)

CVE-2024-43648 厂商页面 (1)

同批安全公告 · Iocharger · 2025-01-09 · 共 16 条

CVE-2024-43658iocharger 安全漏洞
CVE-2024-43661iocharger 安全漏洞
CVE-2024-43654iocharger 安全漏洞
CVE-2024-43655iocharger 安全漏洞
CVE-2024-43657iocharger 安全漏洞
CVE-2024-43662iocharger 安全漏洞
CVE-2024-43653iocharger 安全漏洞
CVE-2024-43656Iocharger 安全漏洞
CVE-2024-43663iocharger 安全漏洞
CVE-2024-43652iocharger 安全漏洞
CVE-2024-43650iocharger 安全漏洞
CVE-2024-43649iocharger 安全漏洞
CVE-2024-43659iocharger 安全漏洞
CVE-2024-43651iocharger 安全漏洞
CVE-2024-43660iocharger 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2024-43648

暂无评论


发表评论