NA

CVE-2020-8006

Published: 12/04/2024 Updated: 12/04/2024

Vulnerability Summary

The server in Circontrol Raption up to and including 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.

Exploits

The server in Circontrol Raption versions through 5112 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 562) is vulnerable to OS command injection ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Circontrol EV Charger vulnerabilities (CVE-2020-8006, CVE-2020-8007) <!--X-Subject-Header-End--> <!--X-Head-of-Message ...