← 戻る
CVE-2026-44107
high
CVSS 7.5
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
概要
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
AI要約 openai / gpt-4o
この脆弱性は、Modbus TCPを通じて認証なしに充電コントローラを再起動できるというものです。Modbus機能が有効で、CharxModbusServerがリッスンしているポートが開いていると、攻撃者がサービス拒否攻撃を実行できる可能性があります。
❓ 何が問題か
Modbus TCPを通じた充電コントローラの再起動
📍 影響範囲
CharxModbusServerがリッスンするポート
🔥 重要度
未認証の攻撃者によるサービス拒否攻撃が可能
🔧 修正方法
Modbus機能の無効化やポートの制限を実施する
🛡️ 暫定回避
情報なし
🔍 検知方法
異常トラフィックを監視し、Modbusポートの不正アクセスを検知する