PT-2023-31423 · Dalmann · Ocpp.Core

Gaetano Coppoletta

·

Publicado

2023-12-07

·

Atualizado

2023-12-13

·

CVE-2023-49957

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dalmann OCPP.Core versions prior to 1.3.0
Description An issue was discovered in Dalmann OCPP.Core for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors.
Recommendations For versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the same connectorId and idTag for multiple transactions to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-49957

Produtos afetados

Ocpp.Core