PT-2023-31920 · Steve Community · Ocpp-Jaxb

CVE-2023-52096

·

Published

2023-12-26

·

Updated

2024-01-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SteVe Community ocpp-jaxb versions prior to 0.0.8
Description The issue generates invalid timestamps, such as ones with month 00, in certain situations. This can occur when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000. The invalid timestamps may lead to a SQL exception in applications and undermine the integrity of transaction records.
Recommendations For versions prior to 0.0.8, update to version 0.0.8 or later to resolve the issue. As a temporary workaround, consider validating the timestamp parameter in the StartTransaction Open Charge Point Protocol message to prevent invalid timestamps from being processed. Restrict access to the vulnerable ocpp-jaxb module to minimize the risk of exploitation until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-52096

Affected Products

Ocpp-Jaxb