CVE-2023-29114
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
05/11/2024
Last modified:
05/11/2024
Description
System logs could be accessed through web management application due to a lack of access control.<br />
<br />
<br />
An attacker can obtain the following sensitive information:<br />
<br />
• Wi-Fi access point credentials to which the EV charger can connect.<br />
<br />
• APN web address and credentials.<br />
<br />
• IPSEC credentials.<br />
<br />
• Web interface access credentials for user and admin accounts.<br />
<br />
• JuiceBox system components (software installed, model, firmware version, etc.).<br />
<br />
• C2G configuration details.<br />
<br />
• Internal IP addresses.<br />
<br />
• OTA firmware update configurations (DNS servers).<br />
<br />
All the credentials are stored in logs in an unencrypted plaintext format.
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM



