Everest · Everest · CVE-2024-37310
**Name of the Vulnerable Software and Affected Versions**
EVerest versions prior to 2024.3.1
EVerest versions prior to 2024.6.0
**Description**
EVerest is an EV charging software stack. An integer overflow in the `v2g incoming v2gtp` function in the v2g server.cpp implementation can allow a remote attacker to overflow the process' heap.
**Recommendations**
For versions prior to 2024.3.1, update to version 2024.3.1 or later.
For versions prior to 2024.6.0, update to version 2024.6.0 or later.
As a temporary workaround, consider disabling the `v2g incoming v2gtp` function until a patch is available.