CVE-2024-44843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/04/2025
Last modified:
25/04/2025

Description

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:*