Record summary

CVE-2023-46359 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALcPH2 Charging Station v1.87.0 - OS Command InjectionCVSS 9.8

An OS command injection vulnerability in Hardy Barth cPH2 Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.

Impact

Unauthenticated attackers can exploit OS command injection through the connectivity check feature to execute arbitrary system commands and completely compromise cPH2 charging station installations.

Remediation

Fixed in version 2.0.0

WeaknessesCWE-78
Authorsmlec
Template tagscve2023cvesalia-plcccph2rcehardy-barthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:hardy-barth:cph2_echarge:-:*:*:*:*:*:*:*
Shodan: html:"Salia PLCC"

Source: ProjectDiscovery

References

3