Nuvation Energy BMS Client-side Authentication
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
In short
Nuvation Battery Management System has a flaw that allows attackers to bypass authentication and gain unauthorized access to the system without valid credentials. This is critical because it exposes battery management controls to anyone who can reach the application.
Technical detail
CWE-603 (client-side authentication) flaw in Nuvation BMS up to version 2.3.9 permits authentication bypass, likely due to insufficient server-side validation of client-side security controls. An attacker can access protected functionality and resources without providing valid credentials, compromising confidentiality and integrity of the battery management system.
Summary generated and translated by AI from the official description.
A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y
Affected products
Nuvation Energy · Battery Management System