PT-2023-31423 · Dalmann · Ocpp.Core
Gaetano Coppoletta
·
Publicado
2023-12-07
·
Atualizado
2023-12-13
·
CVE-2023-49957
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dalmann OCPP.Core versions prior to 1.3.0
Description
An issue was discovered in Dalmann OCPP.Core for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same
connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors.Recommendations
For versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the same
connectorId and idTag for multiple transactions to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ocpp.Core