PatchSiren cyber security CVE debrief
CVE-2024-4622 alpitronic CVE debrief
CVE-2024-4622 describes a default credential vulnerability in alpitronic Hypercharger EV charging devices. When the web interface is exposed and default credentials remain unchanged, attackers can leverage publicly known credentials to gain administrative access. The vulnerability carries a HIGH severity CVSS 8.2 score, reflecting significant availability impact potential. CISA published this advisory on May 9, 2024, with alpitronic providing coordinated response including direct client notification, interface disablement for exposed devices, and production changes to enforce unique passwords.
- Vendor
- alpitronic
- Product
- Hypercharger EV charger
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-09
- Original CVE updated
- 2024-05-09
- Advisory published
- 2024-05-09
- Advisory updated
- 2024-05-09
Who should care
Organizations operating alpitronic Hypercharger EV charging infrastructure, particularly those with remote management requirements or internet-connected charging networks. Critical infrastructure operators, EV fleet managers, and facility security teams responsible for OT/ICS network segmentation should prioritize assessment.
Technical summary
The alpitronic Hypercharger EV charger's web interface, when misconfigured for network exposure, relies on authentication that can be bypassed using publicly known default credentials. Successful authentication grants administrative device access. The vulnerability is network-exploitable with low attack complexity, requiring no privileges or user interaction. CVSS 3.0 scoring emphasizes availability impact (A:H) with limited confidentiality impact (C:L). alpitronic's response includes production changes mandating unique passwords, automatic password reassignment for default-configured field devices, and direct client outreach for exposed systems.
Defensive priority
HIGH
Recommended defensive actions
- Immediately inventory all alpitronic Hypercharger EV charging devices and verify web interface exposure status
- Change default credentials on all devices; new devices now ship with unique passwords retrievable via QR code or DMS portal
- Ensure charging device web interfaces are connected only to internal segregated networks with access controls, never exposed to public internet
- Contact Hypercharger support for assistance with newly assigned passwords on field-updated devices
- Review network segmentation for EV charging infrastructure against ICS-CERT recommended practices
Evidence notes
Advisory ICSA-24-130-02 confirms alpitronic Hypercharger EV charger as affected product. CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H yields score 8.2. Remediation timeline indicates vendor-coordinated response with field mitigations and production changes for unique passwords.
Official resources
-
CVE-2024-4622 CVE record
CVE.org
-
CVE-2024-4622 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-05-09