Critical Bug Patched in Schneider Electric Vehicle Charging Station

施耐德电气警告称,其EVLink Parking设备存在严重漏洞,可能允许攻击者获取系统权限。此漏洞与硬编码凭证错误有关,影响v3.2.0-12_v1及更早版本的立式单元。上周施耐德发布了三个针对电动车充电站的修复补丁,包括代码注入(CVE-2018-7801)和SQL注入(CVE-2018-7802)。Kaspersky Lab报告也概述了电子车辆充电站的潜在漏洞。

Vulnerability in electric car charging stations could allow attackers to compromise devices.

Schneider Electric is warning about a critical vulnerability in its EVLink Parking devices – a line of electric vehicle charging stations. The energy management and automation giant said the vulnerability is tied to a hard-coded credential bug that exists within the device that could enable attackers to gain access to the system.

Affected are EVLink Parking floor-standing units (v3.2.0-12_v1 and earlier). The vulnerability (CVE-2018-7800) is one of three fixes issued by Schneider last week (PDF) impacting the electric charging stations. The company also issued warnings and fixes for a code injection vulnerability (CVE-2018-7801) and SQL injection bug (CVE-2018-7802).

The code injection bug is rated high (CVSS 8.8) and “could enable access with maximum privileges when a remote code execution is performed,” according to the security bulletin. The SQL Injection vulnerability “could give access to the web interface with full privileges,” the company said of the bug rated medium (CVSS 6.4).

EVLink Parking stations are typically found at offices, hotels, supermarkets and fleet hubs. The patch can be applied, but the company also offers a number of ways to mitigate risk such as “set up a firewall to block remote/external access except by authorized users.”

It’s unclear what type of additional access an attacker might gain via a compromised EVLink Parking device. The device itself is part of a full EVLink Parking networked solution that includes the charging station, EVLink insights (online portal) and vehicle maintenance and support services. These systems then link to a central system via the cloud for remote management.

A report issued earlier this month by Kaspersky Lab outlined a number of potential vulnerabilities effecting a wide range of electronic vehicle charging stations. Researchers looked into one of the stations, dubbed the ChargePoint Home offering, and found a raft of vulnerabilities (PDF) that could give an attacker unfettered access to the device.

“All an attacker needs to do to conduct an attack is obtain Wi-Fi access to the network the charger is connected to,” Kaspersky Lab researchers said. “Since the devices are made for domestic use, security for the wireless network is likely to be limited. This means that attackers could gain access easily, for example by bruteforcing all possible password options, which is quite common.”

Researchers noted that EV communication protocols are vulnerable to attack as is EV payment systems and the security of backend communications.

Credited for discovering the Schneider bugs is Vladimir Kononovich and Vyacheslav Moskvin, researchers with Positive Technologies.

转载于:https://www.cnblogs.com/luxiaoyi/p/10184086.html

This version contains full core source codes! This is the only difference between this and the normal package! P.A.T.C.H. is a professional solution for applications/games patching and updating. It contains all features you need: installer, patcher, launcher, repairer, patches creator, FTP uploader, etc. An all-in-one, smart and clean solution! It can generate very small patches thanks to its included file binary diffing algorithm. What does it mean? It means that if you change only 5 bytes in your game, P.A.T.C.H. will create a patch that will change only those 5 bytes on users' builds, instead of downloading the entire edited file. Your users will be able to maintain updated their application copies with no pain or headaches, by saving bandwidth and time. Your users will love you! In addition, you will be able to create small-sized patches (and upload them) quickly with included tools! It includes Unity integrated tools and standalone version (if someone prefers to use it). You can export Unity integrated P.A.T.C.H. for each supported platform, thanks to Unity. Standalone P.A.T.C.H. can be compiled for each platform you need with Xamarin/Mono. You can check out this feature in P.A.T.C.H. documentation. P.A.T.C.H. supports each type of application: Unity based or standalone. Main features: - Binary diffing algorithm - Very small patches - Bandwidth saving - Checking for patches hash - Strong patches ZIP compression - A lot of raised event to hook to monitor what P.A.T.C.H. is doing - Encrypted configs - Customizable settings - Very flexible - No tricky configurations, no headaches! - Simple server side - Comes with launcher source code - If download fails, it will take care to download again failed patch for customizable attempts amount - Launching argument to avoid obsolete clients - Patch rollback feature: if patch process fails all changes will be discarded to avoid a build corruption - Hash validation for patched files - Linear and non-linear patches application - Files download over HTTP, HTTPS, FTP and file system - One-click-deploy - FTP Uploader - Installer and Repairer feature - Shortcuts creation - In-game embedded patcher - Self-update feature - WPF and WinForms examples too - Command Line tool
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值