PT-2026-3853 · Everest · Everest
Faeris95
·
Publicado
2026-01-21
·
Atualizado
2026-01-21
·
CVE-2026-23955
CVSS v3.1
4.2
Média
| Vetor | AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EVerest versions prior to 2025.9.0
Description
EVerest is an EV charging software stack susceptible to a memory reading issue. Integer values are incorrectly concatenated to literal strings when generating error messages, leading to pointer arithmetic instead of proper integer representation. This allows a malicious actor to read unintended memory regions, including the heap and the stack.
Recommendations
Update to version 2025.9.0 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Everest