Site navigation

Security Flaws Found in Schneider Electric Vehicle Charging Points

Duncan MacRae

,

Schneider Electric charging point

“Exploitation of these vulnerabilities may lead to serious consequences,” Positive Technologies researchers warned.

Flaws in Schneider Electric vehicle charging stations have been discovered, which could enable attackers to gain remote control over the devices and halt the charging process.

Vladimir Kononovich and Vyacheslav Moskvin, researchers at threat analysis solutions provider, Positive Technologies, detected three vulnerabilities in the Schneider Electric EVlink Parking electric vehicle charging station. These are used at carparks in several countries, including at offices, hotels, supermarkets, fleets and municipals. Affected firmware versions are 3.2.0-12_v1 and earlier. To eliminate the vulnerability, a new firmware version must be installed, which is available on the Schneider Electric official website.

The first vulnerability (CVE-2018-7800) enables access with maximum privileges to the charging station. A hacker can stop the charging process, and switch the device to the reservation mode, which would render it inaccessible to any customer until reservation mode is turned off. They can even unlock the cable during the charging by manipulating the socket locking hatch, meaning attackers could walk away with the cable. Unauthorised execution of such commands may lead to financial losses in the energy sector. For electric car drivers, this means not being able to use their vehicles since they cannot be charged. The vulnerability is marked as critical.

digital transformation 2019 banner

In addition, the researchers revealed a high-risk vulnerability, CVE-2018-7801, that enables criminals to execute arbitrary commands in the system. This bug allows hackers to gain access to the device with maximum privileges.

The third vulnerability, CVE-2018-7802 was rated medium. By exploiting this error, an attacker can bypass authorisation and gain access to the web interface with full privileges.

Paolo Emiliani, industry and SCADA research analyst at Positive Technologies, said: “Schneider Electric products are widely used in countries all over the world where the electric vehicle industry is developing. Exploitation of these vulnerabilities may lead to serious consequences.

“Attackers can actually block electric car charging and cause serious damage to the energy industry.”

Duncan MacRae

Editor

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences