Back to Database
Status published
High
CVE-2023-29117
Authentication Bypass in JuiceBox Web Manager interface
Vulnerability Description
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-29117
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Abdellah Benotsmane (PCAutomotive)
More from Enel X
View All →CVE-2023-29126
Insecure loose comparison in Enel X JuiceBox
Medium
4.2
CVE-2023-29125
Heap overflow in CM_main.exe binary in Enel X JuiceBox
Critical
9
CVE-2023-29122
Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
Medium
6.7
CVE-2023-29121
Exposed TCF agent service in Enel X Juicebox
Critical
9.6
CVE-2023-29120
Unauthorized Remote Command Execution in Enel X Juicebox
Critical
9.6
Affected Vendor
Enel X
View all reports →Affected Software
JuiceBox Pro 3.0 22kW Cellular
Vulnerable Versions:
0
Timeline
Official Publish:
November 5th, 2024
Last Modified:
November 5th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H