The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EVlink Home Smart version v2.0.4.1.2_131
- Schneider Electric EVlink Home Smart version v2.0.3.8.2_128
- Summary
- CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts are limited to port scanning and fingerprinting activities as well as attempts to perform a potential denial of service attack on the exposed SSH interface.
- Remediation
- Version 2.0.5.0.0_134 of EVlink Home Smart includes a fix for this vulnerability that has been automatically deployed since April 19th to all charging stations connected to the Wiser application. Make sure the charging station is connected to the Wiser application to ensure the new version can be downloaded and installed. The installed firmware version can be verified through Wiser application (refer to the settings page for the charging station).
