PT-2026-3850 · Everest · Everest
CVE-2025-68137
·
Publicado
2026-01-21
·
Atualizado
2026-01-23
CVSS v3.1
8.3
Alta
| Vetor | AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EVerest versions prior to 2025.10.0
Description
EVerest is an EV charging software stack. An integer overflow in the
SdpPacket::parse header() function can occur when processing data. Specifically, the current buffer length can be set to 7 after an 8-byte header has been read. This results in a negative value when calculating the remaining length to read, which is then interpreted as a large positive value due to the size t data type. This can lead to an infinite loop or a stack buffer overflow, depending on whether the connection is plain TCP or TLS.Recommendations
Versions prior to 2025.10.0 should be updated to version 2025.10.0 or later.
Exploit
Correção
Infinite Loop
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Everest