PT-2023-31920 · Steve Community · Ocpp-Jaxb

CVE-2023-52096

·

Publicado

2023-12-26

·

Atualizado

2024-01-04

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SteVe Community ocpp-jaxb versions prior to 0.0.8
Description The issue generates invalid timestamps, such as ones with month 00, in certain situations. This can occur when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000. The invalid timestamps may lead to a SQL exception in applications and undermine the integrity of transaction records.
Recommendations For versions prior to 0.0.8, update to version 0.0.8 or later to resolve the issue. As a temporary workaround, consider validating the timestamp parameter in the StartTransaction Open Charge Point Protocol message to prevent invalid timestamps from being processed. Restrict access to the vulnerable ocpp-jaxb module to minimize the risk of exploitation until the update is applied.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-52096

Produtos afetados

Ocpp-Jaxb