PT-2026-3853 · Everest · Everest

Faeris95

·

Publicado

2026-01-21

·

Atualizado

2026-01-21

·

CVE-2026-23955

CVSS v3.1

4.2

Média

VetorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EVerest versions prior to 2025.9.0
Description EVerest is an EV charging software stack susceptible to a memory reading issue. Integer values are incorrectly concatenated to literal strings when generating error messages, leading to pointer arithmetic instead of proper integer representation. This allows a malicious actor to read unintended memory regions, including the heap and the stack.
Recommendations Update to version 2025.9.0 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23955
GHSA-PX57-JX97-HRFF

Produtos afetados

Everest