EVbee Service
- < 1.4.710
A vulnerability allowing an Adversary-in-the-Middle (AitM) attack has been identified in the EVbee Service Android app, specifically in versions prior to 1.4.710. The app uses TLS for encrypted communication with the EVbee server but fails to validate the server's certificate. This flaw enables an attacker to intercept and manipulate the communication between the app and the server. The encryption is weak, utilizing RC4 with a hardcoded key, which could allow an attacker to access sensitive information such as access codes to charging stations. This vulnerability affects the EVbee Service app version 1.4.101.00.
Exploitation of this vulnerability allows for an Adversary-in-the-Middle attack, where an attacker can intercept, decrypt, and potentially manipulate the communication between the EVbee Service app and the EVbee server. This could lead to unauthorized access to sensitive information, such as access codes for charging stations.
Users are advised to update the EVbee Service app to version 1.4.710 or later. Instructions for updating the app can be found on the Google Play Store. Additionally, ensure that the DC Quick Charging Station has connectivity to update the firmware to version 1.5.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.