exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Circontrol Raption Buffer Overflow / Command Injection

Circontrol Raption Buffer Overflow / Command Injection
Posted Mar 28, 2024
Authored by Dariusz Gonda, Abert Spruyt, Alex Salvetti

The server in Circontrol Raption versions through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection.

tags | exploit, web, overflow, root
advisories | CVE-2020-8006, CVE-2020-8007
SHA-256 | 2a13323836730c890a63f333a24fcfb62637513c16193386327b7be986133bb0

Circontrol Raption Buffer Overflow / Command Injection

Change Mirror Download
Circontrol EV Charger vulnerabilities.

1. CVE-2020-8006 Pre-Auth Stack Based Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10)

The server in Circontrol Raption through 5.11.2 has a pre-authentication
stack-based buffer overflow that can be exploited to gain run-time control
of the device as root.

When the server parses the HTTP headers and finds the Basic-Authentication
tag it will call a base64 decode function. This function takes 3 arguments:
an input pointer, an output pointer and a length. During the authentication
flow, the input pointer can be an attacker controlled string of
approximately 4096 characters, and the output pointer is located on the
stack, the length argument is 512. While the length of the stack based
buffer is passed to the decoder it only verifies that it is not smaller than
3.


[Vendor of Product]

https://circontrol.com/

[Affected Product Code Base]

Raption Server - Raption up to 5.11.2

[Affected Component]

OCCP 1.5, OCCP.1.6, PWRSTUDIO

[Attack Type]

Remote

[Impact Code execution]

true

[Impact Denial of Service]

true

[Attack Vectors]

Remote

[Has vendor confirmed or acknowledged the vulnerability?]

true

[Discoverer]

Abert Spruyt, Alex Salvetti, Dariusz Gońda

[Reference]

https://circontrol.com/intelligent-charging-solutions/dc-chargers-series/raption-150/


2. CVE-2020-8007 - Command injection (RCE/authenticated)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L (9.1)

The pwrstudio web application of EV Charger (in the server in Circontrol
Raption through 5.6.2) is
vulnerable to OS command injection via three fields of the configuration
menu for ntpserver0, ntpserver1, and pingip.

[VulnerabilityType Other]

Command Injection

[Vendor of Product]

https://circontrol.com/

[Affected Product Code Base]

Raption Server - up to 5.6.2

[Affected Component]

pwrstudio

[Attack Type]

Remote

[Impact Code execution]

true

[Attack Vectors]

To exploit this issue authorization is required.


[Has vendor confirmed or acknowledged the vulnerability?]

true

[Discoverer]

Abert Spruyt, Alex Salvetti, Dariusz Gońda


[Reference]

https://circontrol.com/intelligent-charging-solutions/dc-chargers-series/raption-150/

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    35 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close