CVE-2024-44843
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
15/04/2025
Last modified:
25/04/2025
Description
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page