CVE-2024-44843

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:*

History

25 Apr 2025, 16:48

Type Values Removed Values Added
First Time Steve-community
Steve-community steve
CPE cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:*
References () https://gist.github.com/Badranh/94359664799db6d4709871f0c353f476 - () https://gist.github.com/Badranh/94359664799db6d4709871f0c353f476 - Exploit, Third Party Advisory
References () https://github.com/steve-community/steve/blob/master/src/main/java/de/rwth/idsg/steve/ocpp/ws/OcppWebSocketHandshakeHandler.java - () https://github.com/steve-community/steve/blob/master/src/main/java/de/rwth/idsg/steve/ocpp/ws/OcppWebSocketHandshakeHandler.java - Product
References () https://github.com/steve-community/steve/issues/1546 - () https://github.com/steve-community/steve/issues/1546 - Issue Tracking

16 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-287

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) Un problema en el proceso de protocolo de enlace de sockets web de SteVe v3.7.1 permite a los atacantes eludir la autenticación y ejecutar comandos arbitrarios mediante el suministro de solicitudes OCPP manipuladas.

15 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 21:15

Updated : 2025-04-25 16:48


NVD link : CVE-2024-44843

Mitre link : CVE-2024-44843

CVE.ORG link : CVE-2024-44843


JSON object : View

Products Affected

steve-community

  • steve
CWE
CWE-287

Improper Authentication